# ANSSI Flags Metabase SQLi, npm Supply-Chain Worm

Published: 2026-09-14 · Severity: high · Sectors: technology
Canonical: https://vorant.io/reports/746970c4-e83a-50c1-b371-f751de2bfd41/anssi-flags-metabase-sqli-npm-supply-chain-worm

> CERT-FR's weekly bulletin reports active exploitation of a critical Metabase SQLi flaw, a Shai-Hulud npm worm reinfecting AntV packages, and dozens of actively exploited critical CVEs.

CERT-FR's weekly activity bulletin (week 37, 2026) rounds up the most significant vulnerabilities disclosed between 7-13 September 2026 and flags two active incidents. The first is a critical, unauthenticated SQL-injection vulnerability in Metabase (referenced as CVE-2026-72898 in related CERT-FR material) that grants attackers administrator rights on the instance; CERT-FR states it is aware of numerous real-world Metabase compromises and provides detection signatures (a POST to /api/session/reset_password returning HTTP 400 followed by a GET to /api/user/current returning HTTP 200) along with remediation steps including revoking all sessions, rotating API keys and database credentials, and auditing admin accounts.

The second incident is a supply-chain compromise: on 7 September 2026 several npm packages published under the AntV namespace (feishu-docx-mcp@0.3.2, bmc-i18n-extract-cli@1.1.1, blueai-cli@0.7.0, bmc-translate-utils@1.1.1) were found trojanized with a known variant of the Shai-Hulud self-propagating worm, per Aikido Security's blog. This marks a resurgence of the Shai-Hulud npm worm campaign; defenders using these package/version combinations should treat them as compromised and follow standard npm supply-chain incident response (credential rotation, dependency pinning review, CI/CD secret rotation).

Separately, the bulletin catalogs a large volume of vulnerability advisories issued that week, many carrying CVSS scores of 9.0-10 and flagged by NVD as actively exploited, including flaws in GitLab CE/EE, Adobe Commerce/Magento, IBM Db2, Microsoft Edge and Windows, Roundcube Webmail, N-Able N-Central, ConnectWise ScreenConnect, Citrix NetScaler, MikroTik RouterOS, and JFrog Artifactory. A further long tail of critical, not-yet-confirmed-exploited CVEs spans SAP, Adobe ColdFusion, Check Point Spark/Security Gateway, Palo Alto Prisma Access Browser, Google Chrome, Android, and dozens of Windows/Office RCE bugs from Microsoft's September Patch Tuesday. Defenders should prioritize patching the confirmed-exploited items first, then work through the broader critical list per standard risk-based patch management.

## Mentioned in this report

- Vulnerabilities: CVE-2018-1273 (KEV), CVE-2026-19490 (KEV), CVE-2026-28606, CVE-2026-41157, CVE-2026-42016 (KEV), CVE-2026-42018 (KEV), CVE-2026-44756, CVE-2026-48273, CVE-2026-49921, CVE-2026-54433, CVE-2026-58240, CVE-2026-58822, CVE-2026-65669, CVE-2026-66768, CVE-2026-67277 (KEV), CVE-2026-68839, CVE-2026-69276, CVE-2026-69408, CVE-2026-69414, CVE-2026-69854, CVE-2026-72898 (KEV), CVE-2026-75650 (KEV), CVE-2026-75746, CVE-2026-78445, CVE-2026-78509, CVE-2026-78510, CVE-2026-79282, CVE-2026-79290, CVE-2026-81963 (KEV), CVE-2026-84869 (KEV), CVE-2026-85046 (KEV), CVE-2026-85102, CVE-2026-85103, CVE-2026-85706 (KEV), CVE-2026-85880 (KEV), CVE-2026-86060 (KEV), CVE-2026-86218 (KEV), CVE-2026-87438, CVE-2026-87544, CVE-2026-87719

Source reporting: https://www.cert.ssi.gouv.fr/actualite/CERTFR-2026-ACT-039

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/746970c4-e83a-50c1-b371-f751de2bfd41/anssi-flags-metabase-sqli-npm-supply-chain-worm.
Full IOC sets, deployable detections, the entity graph, TAXII 2.1 feed and real-time alerts: https://vorant.io/signup
