ao link
Menu
Teiss - Cracking Cyber Security
Teiss - Cracking Cyber Security

Framework discloses data breach tied to Metabase zero-day attack

A previously unknown vulnerability in a third-party analytics platform allowed a hacker to reach customer contact records at the laptop maker, the company said.

Linked InXFacebook
bookmark_borderSave to Library

Framework Computer, a San Francisco-based manufacturer of modular and repairable laptops, has disclosed a data breach that exposed customer contact records after an intruder exploited a zero-day vulnerability in Metabase, the outside business intelligence platform the company uses to analyze internal data. Framework began alerting affected customers on the evening of Thursday, August 6, saying the exposed information included names, email addresses, physical addresses, phone numbers and login IP addresses.


The breach traces back to an undisclosed flaw in Metabase Cloud, a hosted analytics service used by more than 100,000 clients, including McDonald’s, T-Mobile and Hugging Face. Metabase issued its own security notice on August 6, stating that the vulnerability struck installations running version 1.58 and later. The intruder exploited the flaw to inject unauthorized SQL commands into the application’s database, a method capable of granting administrator-level control and exposing stored database credentials. Metabase said the exposure affected both its cloud-hosted customers and organizations running the software on their own servers.


Framework spokesperson Eric Schumacher told TechCrunch the breach reached "all customers," though he did not provide a specific figure. The company said it is still determining whether accounts tied to its business-tier service, Framework for Business, were also affected.


Notifications sent to customers and shared on Reddit and the Framework Community forum detailed the scope of the exposed records: full names, email addresses, login IP addresses, and complete billing and shipping information, including country, street address, city, state, ZIP code and phone number. For business accounts, Framework said it was examining whether company phone numbers, tax identification numbers and billing email addresses were also compromised. It remains unclear whether the intruder downloaded the full set of exposed data.


Framework said payment details, order histories and other personal information outside the listed categories were not part of the compromised data. Even without financial data involved, security officials note that leaked names, addresses and phone numbers can fuel convincing phishing and impersonation schemes.


Once Metabase alerted Framework to the intrusion, the laptop maker rotated all credentials connected to the databases linked to its analytics environment. Framework said its review turned up no sign that administrative access had been altered or that any systems outside the Metabase environment were compromised. The company is now auditing how much internal data it shares with outside analytics tools and intends to restrict access to only the specific data columns required for analysis.


Metabase’s advisory outlined the mechanics of the attack, which centered on the platform’s password-reset function. The sequence began with a request sent to the password-reset endpoint, followed by a follow-up call to retrieve current user information, according to the technical breakdown Metabase published alongside a related advisory posted to GitHub. Metabase said it has since blocked the exploited endpoints, deployed a patch and upgraded all affected cloud accounts. The company urged customers running the vulnerable software on their own infrastructure to update immediately and rotate any credentials linked to connected databases, cautioning that its investigation is ongoing and that findings so far remain preliminary.


Tally, an automated accounting and financial management platform, is also known to have been affected by the same Metabase vulnerability, though the extent of any exposure at that company has not been made public.


Framework urged customers to treat unsolicited emails or calls referencing their account with caution, recommending they verify the sender’s domain against official Framework addresses and log into their accounts directly through the company’s website rather than following links in messages. The company said it would issue further notifications if Metabase’s ongoing investigation uncovers additional impact, and advised customers to watch for unusual login activity on their accounts.

Linked InXFacebook
bookmark_borderSave to Library
Teiss - Cracking Cyber Security

Subscribe to our Weekly Newsletter

Receive the latest insights direct to your inbox, and gain access to our exclusive events.
Teiss - Cracking Cyber Security

Winston House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF

 

020 8349 4363

info@teiss.co.uk

 © 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543