Short answer
Framework notified laptop customers of a data breach after Metabase disclosed a zero-day vulnerability that allowed unauthorized access to customer data stored in its business intelligence platform. Names, emails, phone numbers, and billing addresses were exposed, but payment and order information remains secure.
Key Takeaways
Key Takeaways
- Framework disclosed a data breach affecting customer contact and billing information after Metabase's Cloud platform was compromised via a zero-day vulnerability
- The breach exposed names, email addresses, phone numbers, shipping and billing addresses, company names, and login IP addresses
- Payment data and order information were NOT compromised according to Framework
- Metabase patched the vulnerability across versions 0.58.24, 0.59.21, 0.60.17, 0.61.11, 0.62.9, and 0.63.5
- Framework rotated database credentials and is reviewing data shared with third-party analytics vendors
The Breach Explained
Framework, the modular laptop company known for its repair-friendly designs and customer community, disclosed a data breach on August 6, 2026. The incident stemmed from a vulnerability in Metabase Cloud, a business intelligence and analytics platform that Framework uses to store customer data.
Metabase discovered the attack on August 3, 2026. The vulnerability was a zero-day flaw in Metabase Cloud versions 1.58.0 and above that allowed unauthenticated SQL injection through the /api/session/reset_password endpoint. This technical flaw enabled attackers to gain administrator access, steal credentials, and export data without authorization.
Metabase notified Framework at 9:00 AM Pacific Time on August 6. Framework then proceeded to alert affected customers shortly after receiving that notification. The speed of disclosure stood out in community discussions, with customers noting the company's transparency and timeliness compared to typical breach notification delays.
What Data Was Exposed
According to Framework's breach notification, the compromised information included customer contact details and location data. Specifically, the exposed data fields were:
- Full names
- Email addresses
- Phone numbers
- Billing addresses
- Shipping addresses
- Company names (for business customers)
- Login IP addresses
Framework was explicit about what was NOT compromised. The company confirmed that order information and payment data, including credit card numbers and billing details, were not accessed or exposed through this breach. This distinction matters because it limits the immediate financial risk to affected customers, though the personal data exposure still carries privacy and identity theft concerns.
How the Vulnerability Worked
The Metabase vulnerability (tracked as GHSA-vwf4-m7j8-wcjf) exploited an unauthenticated endpoint that should have required verification. The /api/session/reset_password endpoint, designed for password recovery flows, could be manipulated through SQL injection to bypass authentication controls.
Once attackers gained access through this vector, they obtained administrator-level privileges within the Metabase Cloud environment. This elevated access allowed them to export data that should have remained secure, including the customer information Framework stored for business intelligence purposes.
Metabase responded by blocking the attack endpoints, releasing patches across multiple versions, notifying law enforcement, and engaging a third-party forensic firm to investigate the scope and impact of the compromise.
What Customers Should Do
Framework customers who received breach notification emails should take the following steps:
- Change passwords on any accounts associated with the exposed email address, particularly if the same password is used elsewhere
- Enable two-factor authentication on important accounts if not already active
- Monitor accounts for unusual activity, especially login attempts from unfamiliar locations
- Be alert for phishing attempts that may reference the breach to trick customers into revealing additional information
The exposed login IP addresses mean attackers may have visibility into when and where affected customers accessed their accounts, which could inform targeted social engineering attempts.
Why Third-Party Analytics Platforms Matter
This breach highlights an increasing attack vector: third-party business intelligence and analytics platforms. Companies increasingly rely on tools like Metabase to store and analyze customer data, but those platforms become single points of failure. When the analytics provider is compromised, every customer data store connected to it is exposed.
Framework's response includes evaluating what data it shares with business intelligence vendors going forward. This review suggests the company may tighten data retention policies or limit the granularity of customer information stored in third-party systems.
What's Next
Metabase has released patched versions across its supported release lines. Users running affected versions should upgrade immediately to 0.58.24, 0.59.21, 0.60.17, 0.61.11, 0.62.9, or 0.63.5 depending on their current release.
Framework has rotated database credentials and confirmed no changes were made to admin access or systems outside of Metabase. The company is conducting its own review of data sharing practices with analytics vendors.
For Framework customers, the breach represents a privacy incident rather than a financial one, but the personal data exposed is exactly the type of information identity thieves target. Vigilance over the coming months is advisable.
FAQ
FAQ
<h3>Q: Was my payment information compromised in the Framework breach?</h3>
<p>No. Framework confirmed that order information and payment data were not accessed or exposed through this breach. The compromised data was limited to contact and billing address information stored in Metabase.</p>
<h3>Q: When did Framework discover the breach?</h3>
<p>Metabase discovered the attack on August 3, 2026. Framework was notified at 9:00 AM Pacific Time on August 6, 2026, and sent breach notifications to customers shortly after.</p>
<h3>Q: What specific data was exposed?</h3>
<p>The breach exposed names, email addresses, phone numbers, billing and shipping addresses, company names, and login IP addresses. Payment information and order details were not compromised.</p>
<h3>Q: What version of Metabase was vulnerable?</h3>
<p>The vulnerability affected Metabase Cloud versions 1.58.0 and above. Patched versions include 0.58.24, 0.59.21, 0.60.17, 0.61.11, 0.62.9, and 0.63.5.</p>
<h3>Q: How should affected customers respond?</h3>
<p>Affected customers should change passwords on accounts linked to exposed email addresses, enable two-factor authentication where possible, monitor accounts for suspicious activity, and be alert for phishing attempts that may reference the breach.</p>
Conclusion
Framework's breach through Metabase underscores the risks of trusting customer data to third-party analytics platforms. While payment data remains secure, the exposure of personal contact information warrants vigilance from affected customers. The rapid disclosure timeline offers a model for how companies should handle similar incidents.
What are your thoughts on Framework's transparency in this situation? Share your opinion in the comments.
Top comments (0)