Framework Data Breach: Community Reacts to 6-Hour Disclosure
Framework discloses data breach via Metabase 0-day

Framework disclosed a limited data breach via a Metabase 0-day, leaking customer information but no billing details. The community praises the rapid notification—Metabase took 3 days, Framework only 6 hours—but some members express frustration over third-party data sharing and demand assurance that credit card info was safe. Framework says it's evaluating data shared with business intelligence platforms.
It seems like most companies wait months (at minimum) before notifying customers (if they do at all) because they think any security issue will cause the public to lose trust in them.
- wkjagt
At some point I almost bought a Framework laptop, just didn't click the Order button. I had my address etc already filled in, so because of that I also got that email from Framework this morning. From a technical perspective I guess it makes sense that Metabase has my personal information, but it's still kind of crazy to think how much personal information you're sending "out there" just by, for example, checking a final price of a product including shipping.
- chocolatkey
Here's what an email from metabase looks like for those affected:
On Monday, August 3, we discovered that Metabase Cloud was attacked by someone utilizing an unknown (“0-day”) security vulnerability in versions 1.58 and above. We immediately blocked the endpoints used for the attack, then quickly identified and patched the vulnerability. We notified law enforcement, and we have engaged with a third party forensics firm to conduct an independent investigation.
Your instance of Metabase was vulnerable to this 0-day. Therefore, to protect your company, we recommend you:
Rotate the credentials for every database connected to your instance; and
Review the admin accounts on your instance and remove anything you don't recognize.
We also discovered that the attacker was able to gain access to your instance. We created a report on the actions we believe the attacker took on your instance, which includes log files, and which you can get from the Metabase Store at https://store.metabase.com.
(If you do not have access to the Metabase Store, are having issues accessing the report, or do not want to click on a link in an unexpected email, you can log into your instance directly and reach us at Help > Get help in the grid menu in the upper right hand corner. We'll confirm this message is from us and email you the report.)
This report is based on our own application logs. We did not query or read the data in your connected databases.
Depending on the jurisdictions i […]
- pelagicAustral
Metabase again?? Last 0day was catastrophic. My previous employer moved all that infrastructure back to on-prem, I guess he must be laughing now.
- parable
While I'm impressed with Framework's handling of this issue, I can't help but notice how this was yet another analytics platform breach. CRM tools and analytics platforms (Salesforce, Mixpanel, now Metabase - I'm sure I'm forgetting some) are common vectors to get access to customer metadata these days.
I don't see a solution to this in the near future. I initially thought up something quite simple: assign every customer a unique ID and use that where possible to reference a customer. That solution, however, renders the analytics and CRM tools nearly useless. There has to be a better way, though, other than haphazardly giving out customer metadata to other vendors. All of that information should stay in-house.
As for why metadata is important: I've said this before, but metadata can't easily be changed. I'd much prefer having my password or credit card number leaked in plaintext since I can change those identifiers trivially. I can't change my name, phone number, or address as easily.
- OroPla
A bit ironic that I found out about this through this website first despite also having received a mail from Framework about the issue.
Still not sure what to do with this information. It's not like I can change any of the compromised information.