Framework, the maker of modular and repairable laptops, has disclosed a data breach that exposed customer contact information after a zero-day vulnerability was exploited at Metabase, its third-party business intelligence and analytics provider. The company began notifying affected users on the evening of Thursday, August 6, confirming that names, email addresses, physical addresses, phone numbers, and login IP addresses were accessed by an unauthorized party.

The incident originated with a previously unknown flaw in Metabase Cloud, the hosted analytics service used by Framework to visualize and analyze internal data. Metabase issued its own security alert on August 6, warning that the vulnerability affected versions 1.58 and above of its software. The attacker was able to inject arbitrary SQL commands into the application database, a technique that can potentially grant administrator-level access and expose stored database credentials. Metabase noted that both its cloud-hosted and self-hosted customers were at risk.

Framework spokesperson Eric Schumacher told TechCrunch that the breach affected “all customers,” though he declined to provide a specific number. The company is still investigating whether business-tier accounts were also impacted. According to customer notifications shared on Reddit and the official Framework Community forum, the accessed data fields include full names, email addresses, login IP addresses, and detailed billing and shipping address blocks containing country, street address, city, state, ZIP code, and phone numbers. For Framework for Business accounts, the company is also reviewing whether fields such as company phone number, VAT or EIN identifiers, and billing email addresses were exposed.

Framework emphasized that payment information, order records, and other personally identifiable information beyond the listed contact fields were not part of the accessed data set. That distinction is critical for customers monitoring their financial accounts, though the stolen contact details still create significant risk for targeted phishing and social engineering attacks.

Once notified by Metabase, Framework immediately rotated all credentials associated with its databases connected to the analytics instance. The company said it found no evidence of changes to administrative access or any compromise of systems outside the Metabase environment. Framework is also conducting an internal review of how much data it shares with external business intelligence tools and plans to limit column-level access strictly to what is necessary for analysis.

Metabase documented the attack pattern in a security advisory, describing a sequence involving the password-reset endpoint. The chain begins with a POST request to /api/session/reset_password, followed by a GET request to /api/user/current. A related advisory has been published on GitHub. Metabase said it has already blocked the attack endpoints, patched the vulnerability, and upgraded all affected cloud customers. Self-hosted users running vulnerable versions are urged to upgrade immediately and rotate any credentials tied to their connected databases. The vendor cautioned that its investigation remains ongoing and that its early findings are preliminary.

At least one other company, the automated accounting and financial management platform Tally, is known to have been affected by the same Metabase zero-day. The scope of exposure at Tally has not been publicly detailed.

For Framework customers, the immediate concern is the potential for highly convincing phishing campaigns. Attackers in possession of names, email addresses, physical addresses, and phone numbers can craft fraudulent support emails or phone calls that appear legitimate. Framework advised customers to verify any unexpected communications by checking the sender’s domain against official Framework addresses and to log into their accounts directly through the company’s website rather than clicking links in unsolicited messages. The company said it will send a follow-up notification if Metabase reports any additional impact. Customers should also monitor for unusual login attempts and remain vigilant against identity scams that leverage the leaked contact data.