Framework

Framework

Modular, upgradeable laptops for sustainable computing

Overview

Framework makes modular, upgradeable laptops that are designed to last, focusing on sustainability and repairability. Its products, the Framework Laptop 13 and 16, let users swap and upgrade components such as processors, memory, and storage to keep up with technology. Unlike many laptops with fixed designs, Framework emphasizes removable modules and easy upgrades, while also discounting older generations to invite more customers into the ecosystem. The company aims to reduce electronic waste by offering durable, customizable devices that customers can repair and extend.

About Framework

Simplify's Rating
Why Framework is rated
C+
Rated B on Competitive Edge
Rated B on Growth Potential
Rated D+ on Differentiation

Industries

Hardware

Industrial & Manufacturing

Design

Consumer Goods

Company Size

51-200

Company Stage

Early VC

Total Funding

$45.3M

Headquarters

San Francisco, California

Founded

2019

Get referred to Framework

See people who can refer or advise you

Simplify Jobs

Simplify's Take

What believers are saying

  • August 18 2026 Laptop 12 adds Core Series 3, Wi-Fi 7, Thunderbolt 4.
  • Laptop 12 now ships prebuilt with Fedora 44, matching Framework's Linux-heavy user base.
  • April 2026 Laptop 13 Pro launched with Ubuntu certification and strong preorder demand.

What critics are saying

  • August 2026 Metabase breach exposed all customers' names, phones, addresses, and login IPs.
  • June 2026 BIOS 3.20 bricked Ryzen 7040 boards, forcing motherboard replacements and support backlash.
  • Repeated breaches and bricking incidents destroy trust, then kill the repairability premium entirely.

What makes Framework unique

  • Framework sells modular laptops with user-replaceable mainboards, keyboards, batteries, and ports.
  • Its ecosystem spans Laptop 12, 13, 13 Pro, 16, and desktop parts.
  • It pairs repairability with official Linux support and community-facing documentation.

Help us improve and share your feedback! Did you find this helpful?

Funding

Total Funding

$45.3M

Above

Industry Average

Funded Over

5 Rounds

Series A funding typically happens when a startup has a product and some customers, and now needs funding to scale. This money is usually used to grow the team, expand marketing, and improve the product. Venture capital firms are frequently the main investors here.
Series A Funding Comparison
Above Average

Industry standards

$15M
$8.2M
Discord
$15M
Canva
$17M
Framework
$30M
Kalshi

Benefits

Health Insurance

Company Equity

Paid Vacation

Paid Parental Leave

Flexible Work Hours

Remote Work Options

401(k) Retirement Plan

401(k) Company Match

Growth & Insights and Company News

Headcount

6 month growth

3%

1 year growth

1%

2 year growth

0%
Ars Technica
Aug 19th, 2026
Framework responds to complaints that BIOS update bricks Ryzen 7040 laptops.

Framework responds to complaints that BIOS update bricks Ryzen 7040 laptops. Framework says it's replacing some out-of-warranty AMD mainboards. A BIOS update for the Framework Laptop 13 with AMD Ryzen 7040-series processors is bricking the systems, multiple users have reported online. Framework started shipping pre-built Ryzen 7040-based Framework Laptop 13 computers and compatible motherboards in 2023. In June 2026, Framework released BIOS 3.20 for the devices. The update adds mainboard support for features, including a haptic touchpad and new speakers, for the higher-end Framework Laptop 13 Pro and fixes issues, including one "where the Battery Extender status was reported incorrectly following a reboot, hibernation, or shutdown after the timer had expired," per a post on Framework's forum from an employee. Some users say that they installed the update successfully. "[T]he update process seems to have stalled," a Framework forum user named Sven posted in July. "What I see is a black screen and a progress bar with 2 dots and then the Framework logo. The progress bar is not moving for about 3 hours now. Also, I can't turn off the Framework using the power button, no matter how long I hold it down. Now the BIOS update is stuck, and I can not power down or reboot the machine." Ars Technica contacted Framework, asking how many customers are affected. In a company statement, Framework said it has "received reports of a small percentage of Framework Laptop 13 7040 Series BIOS updates resulting in non-bootable boards." Framework is investigating the root cause of the issue, the statement said. There are reports of users having problems with BIOS upgrades on Ryzen 7040-based Framework Laptop 13 devices going back to at least March 2025. After the most recent BIOS update, some users reported that Framework support told them they needed a new motherboard, but Framework wouldn't provide it for free because the customer was past warranty. Framework's statement to Ars says: ... in addition to replacing in-warranty Mainboards, we are making exceptions for out-of-warranty replacements where we can confirm a stable-release BIOS update caused the board to become non-bootable. Framework is also introducing a "Crisis Recovery Mode" BIOS functionality to enable a path for failed updates to be directly recoverable. "Our latest Framework Desktop BIOS release includes this functionality, and we are actively bringing it to Framework Laptop 12, 13, and 16 in our upcoming BIOS release cycles for each," Framework said. We won't be sure of the source of the problems until Framework provides more information. Blogger Guanzhong Chen, however, wrote a detailed blog post this week about their purported experience with their motherboard breaking and suggested the problem stems from "some bug with the software that caused it to display what appears to be random memory on the screen, especially when this has happened before to other people for other BIOS versions." The software developer, who was ultimately able to flash the firmware onto their motherboard after a support representative reportedly told him to buy a new one, added: "At the same time, it somehow flashes the BIOS slower in regular operation than a cheap 15 MHz programmer over pogo pins, which really makes you wonder what it's doing under the hood." Scharon is a Senior Technology Reporter at Ars Technica writing news, reviews, and analysis on consumer gadgets and services. She's been reporting on technology for over 10 years, with bylines at Tom's Hardware, Channelnomics, and CRN UK.

The Verge
Aug 19th, 2026
Framework gave its 12-inch laptop some hardware upgrades.

Framework gave its 12-inch laptop some hardware upgrades. The Laptop 12 has new Intel chips, a Linux option, a fingerprint reader, and a backlit keyboard. by Jess Weatherbed Aug 19, 2026, 3:14 AM PDT If you buy something from a Verge link, Vox Media may earn a commission. See our ethics statement. Image: Framework Jess Weatherbed is a news writer focused on creative industries, computing, and internet culture. Jess started her career at TechRadar, covering news and hardware reviews. Framework has refreshed its 12-inch convertible laptop, introducing Intel's latest Core Series 3 processors, expanded hardware customizations, and a pre-built Linux option. The cheapest pre-built base configuration for the Framework Laptop 12 now starts at $699 - $100 less than the previous version when it launched last year. Preorders are open now, with the first wave of deliveries expected to ship in October. That pre-built base configuration is only available in green, and includes an Intel Core 3 304 CPU, 8GB of RAM, and 512GB of storage. It also comes preloaded with Linux Fedora 44 KDE Plasma, a decision brought on by Framework finding that almost 80 percent of Laptop 12 owners are already running Linux "across a range of distros." You can still configure the updated laptop to come with Microsoft's Windows 11 Home operating system instead, but doing so will increase the price by $100. Framework says that the Core Series 3 is "purpose built for smaller, lower-power, entry-priced laptops," and should help to improve battery life, temperatures, and fan noise on the more powerful chip options. The Core 3 304 chip only has one performance core, however, and the only laptop we've tested with this Intel Wildcat Lake processor left us bitterly disappointed. That chip update does allow for a smattering of internal hardware and port improvements, including higher DDR5 memory speeds of up to 6400 MT/s, Wi-Fi 7 R2, and Thunderbolt 4 support for the rear two Expansion Card slots, which allows you to plug in two 4K 60Hz displays or eGPUs. One small downgrade is that the front two USB slots are now only USB 3.2 Gen 2, but Framework says all four slots still support power input for charging. For all Core 5 and Core 7 configurations, the Laptop 12 now includes two additional features as standard: a fingerprint reader built into the power button, and a backlit keyboard. The illuminated keyboard is also available as an optional customization on the DIY Edition of the Laptop 12, which starts at $549 and provides more color options compared to the pre-built version. The original Laptop 12 that uses 13th Gen Intel Core chips is still available if none of this entices you, however, and prices now start at $699 for the pre-built version or $499 for the DIY Edition. Follow topics and authors from this story to see more like this in your personalized homepage feed and to receive email updates. * Jess Weatherbed The Verge daily. A free daily digest of the news that matters most.

Echo AI
Aug 15th, 2026
Metabase CVE-2026-72898 SQL Injection: Recap and next steps.

Metabase CVE-2026-72898 SQL Injection: Recap and next steps. Rotem Natan Aug 15, 2026 | 6 Minutes Key takeaways. * Metabase disclosed CVE-2026-72898, an unauthenticated SQL injection vulnerability (CVSS 10.0) that attackers were already exploiting in the wild before a patch existed. * A successful attack grants full admin access, exposing connected database credentials, query access, and configuration control - no login required. * Framework and Tally have both disclosed data theft tied to this exact flaw, so the risk is confirmed, not theoretical. * A patch closes the vulnerability going forward, but it doesn't tell you whether an attacker already got in before you patched - check logs, not just version numbers. * Metabase is an application, not a hardened base image - but running it on a hardened container image shrinks what an attacker can do once inside, which is a different layer of defense than patching the app itself. What happened. Metabase disclosed a previously unknown SQL injection vulnerability, tracked as CVE-2026-72898 (also referenced as GHSA-vwf4-m7j8-wcjf), that attackers had already been exploiting in the wild. The flaw is unauthenticated, rated CVSS 10.0, and can let a remote attacker gain full admin access to a Metabase instance - no credentials, no user interaction, just a crafted request to the public password-reset endpoint. It affects Metabase versions x.58.0 through x.63.4. Fixed versions are: * x.58.x | upgrade to x.58.23 or later * x.59.x | upgrade to x.59.21 or later * x.60.x | upgrade to x.60.17 or later * x.61.x | upgrade to x.61.11 or later * x.62.x | upgrade to x.62.9 or later * x.63.x | upgrade to x.63.5 or later From there, an attacker could: * Access connected database credentials * Query accessible data * Change configurations * Export data This isn't theoretical. Both Framework and Tally have disclosed data theft following compromises of their Metabase environments, and n8n disclosed a related breach tied to its own Metabase instance. If you're self-hosting Metabase, act now. Metabase's own recommendations are direct: * Upgrade immediately to the latest patched release for your version. * Revoke all active user sessions. * Review API keys and admin accounts for unexpected changes. * Rotate credentials for every connected database. * Review warehouse logs, Metabase activity, and query history for suspicious access. If you're on Metabase Cloud, Metabase says you're already patched - but that doesn't mean you weren't affected before the patch shipped. The indicator worth checking right now. One sequence in your logs is a strong signal of exploitation: POST /api/session/reset_password | 400 followed by GET /api/user/current | 200 A failed password-reset request immediately followed by a successful "current user" check is consistent with an attacker using the injection to mint themselves a valid session. If you see this pattern, treat the instance as compromised and start incident response - don't wait for further confirmation. The important part: a patch closes the vulnerability, but it doesn't tell you whether someone got there before you patched. Patching and forensic review are two separate steps, and skipping the second one leaves you blind to whether you're cleaning up after an intrusion that already happened. Is Metabase a base image? No - and that distinction matters. It's worth being precise here, because the terminology gets confused: Metabase is an application - an open-source business intelligence and analytics tool. It is not a base image. A base image is the underlying operating system layer a container is built from - things like Debian, Alpine, or a distroless image. When you run Metabase in a container, that container has two layers: the Metabase application code (where this SQL injection lives) and the base image underneath it (the OS, libraries, and runtime Metabase sits on top of). This vulnerability is entirely in the application layer. No base image, hardened or not, would have patched Metabase's password-reset endpoint - that fix has to come from Metabase itself. But the base image layer still matters here, for a specific reason: it determines what an attacker can do once they're in. An attacker who gains admin access to Metabase through this flaw is now operating inside a running container. Whether that container gives them a shell, a package manager, and a path to pivot further, or whether it's stripped down to exactly what Metabase needs to run, depends entirely on the base image underneath it. Why a hardened base image still reduces your exposure. A hardened container image - one stripped of unnecessary components, built with tight default configurations, and continuously scanned and patched - doesn't stop an application-layer SQL injection. What it does is limit the blast radius if an attacker gets in through one: * No shell or package manager in production images means an attacker with admin access to Metabase has a much harder time pivoting into the underlying host or pulling in additional tooling. * A minimal attack surface means fewer binaries and libraries are present to exploit for privilege escalation or persistence, even after initial compromise. * Continuous rebuilds and fast CVE remediation at the OS layer mean the environment Metabase runs in isn't independently exposing you to a second, unrelated vulnerability while you're already dealing with this one. This is the same logic behind why teams increasingly run applications - Metabase included - on CVE-free base images rather than default upstream images that ship with thousands of known vulnerabilities baked in before a single line of application code runs. The application still needs patching on its own schedule. The base image is what determines how contained an incident stays if that patching happens a day too late. If you're evaluating how your container foundation holds up independent of application-layer bugs like this one, Echo's guides on container image vulnerability best practices and AI-ready hardened container images cover what a genuinely hardened base layer looks like in practice. Faq. Is Metabase itself a hardened base image? No. Metabase is an application that runs inside a container, typically on top of a base image like Debian or Alpine. A hardened base image refers to that underlying OS layer, not to Metabase's own code. The two are separate layers of the same deployment, and this vulnerability lives entirely in Metabase's application code. Does a hardened base image protect against this SQL injection? Not directly - the flaw is in Metabase's password-reset endpoint, so only a Metabase patch fixes it. A hardened base image reduces what an attacker can do after gaining access, by removing shells, package managers, and unnecessary components that would otherwise help them pivot further inside the container or host. How do I know if I was compromised before I patched? Check your logs for a failed POST /api/session/reset_password request immediately followed by a successful GET /api/user/current request - this is the signature of CVE-2026-72898 being exploited. Also review admin accounts, API keys, and warehouse query logs for unexplained changes or access around the time the vulnerability was disclosed. What's the difference between patching Metabase and hardening the container it runs in? Patching Metabase fixes the specific application vulnerability - in this case, the SQL injection in the password-reset flow. Hardening the container's base image is a separate, ongoing practice that reduces the overall attack surface, so that whatever the next application-layer bug turns out to be, the surrounding environment limits how far an attacker can go. Should self-hosted Metabase users do anything beyond upgrading? Yes. Upgrading closes the vulnerability going forward, but it doesn't undo any access an attacker gained beforehand. Revoke active sessions, rotate all connected database credentials, and audit admin accounts and query logs, since the CVSS 10.0 rating and confirmed in-the-wild exploitation mean this wasn't a low-probability risk.

Runtime Revolution
Aug 8th, 2026
Metabase sqli zero-day exploited: data theft attacks confirmed.

Metabase sqli zero-day exploited: data theft attacks confirmed. This article was written by a language model from the source above and was not reviewed by a human before publication. Verify anything operational against the original. Editorial policy Key points * " Metabase Cloud and self-hosted instances are compromised via a critical SQL injection zero-day, leading to customer data theft. * " Affected systems include Metabase versions 1.58 and above, including 0.58.x through 0.63.x branches. * " Immediately upgrade self-hosted Metabase instances to patched versions and follow post-compromise remediation steps. A critical, unauthenticated SQL injection zero-day vulnerability in Metabase, affecting versions 1.58 and above, has been actively exploited in the wild, leading to data theft from customer instances. Metabase, a popular open-source business intelligence platform, disclosed the attacks, confirming that its Metabase Cloud SaaS platform was compromised. Self-hosted installations are also vulnerable if not updated, posing a significant risk to organizations utilizing the platform, according to BleepingComputer. Metabase has identified and blocked the attack endpoints, subsequently rolling out a fix for the vulnerability. This unauthenticated SQL injection flaw allows a remote attacker to gain administrator access to a customer's Metabase instance. With administrative control, attackers can alter application configurations, steal stored credentials for connected databases, access any data available through those connections, and export sensitive information. Technical details of the Metabase sqli zero-day vulnerability. The zero-day, described by Metabase as a 'CRITICAL' vulnerability with a CVSS score of 10.0, enables attackers to inject arbitrary SQL into the Metabase application database. This critical flaw grants immediate administrative access without requiring any prior authentication. The broad capabilities afforded by this access include: * Configuration Manipulation: Attackers can modify Metabase application settings. * Credential Theft: Stored credentials for any connected databases can be exfiltrated. * Data Exfiltration: Any data accessible via database connections can be read and exported. The exploitation of this vulnerability has already impacted several organizations. Laptop manufacturer Framework confirmed that its Metabase instance was compromised on August 3, leading to the theft of customer information. This data included full names, email addresses, login IP addresses, billing and shipping address information, phone numbers, and company names. For Framework for Business customers, additional data such as VAT, EIN, and billing email addresses may also have been exposed. Online form builder Tally also reported a compromise of its Metabase analytics environment on August 3. Attackers accessed email addresses and cryptographic hashes of user passwords. Tally clarified that user forms and submitted answers, stored separately, were not affected. LexisNexis, while not explicitly linking its incident to this specific Metabase API vulnerability, confirmed that its Metabase API was impacted by a cyberattack on a third-party vendor earlier this week, causing service disruptions. Metabase states that all its Cloud customers have been automatically upgraded and patched. However, organizations running self-hosted Metabase instances must perform manual updates to secure their systems against this active threat. Mitigation and remediation for Metabase 1.58+ unauthenticated SQL injection. Given the active exploitation and critical nature of this vulnerability, immediate action is paramount for all self-hosted Metabase users. The following steps are crucial for Metabase 1.58+ unauthenticated SQL injection remediation: * Immediate Upgrade: Update all vulnerable Metabase installations to the patched versions. The minimum safe releases are 0.58.24, 0.59.21, 0.60.17, 0.61.11, 0.62.9, and 0.63.5. * Temporary Workaround: If immediate upgrading is not possible, temporarily block access to the /api/session/reset_password endpoint. This serves as a critical, albeit temporary, measure to prevent exploitation. * Post-Compromise Actions: For any potentially compromised instances, Metabase strongly recommends: * Revoking all active user sessions. * Reviewing API keys and administrator accounts for any unauthorized changes. * Rotating credentials for all connected databases. * Inspecting application logs and query history for signs of compromise. How to detect Metabase data theft compromise. Organizations should actively look for indicators of compromise (IOCs) in their system logs to detect Metabase data theft compromise. Attacks can be identified by a POST request to /api/session/reset_password returning a 400 status code, immediately followed by a successful GET request to /api/user/current. The presence of these entries in system logs strongly suggests that an instance has been compromised, and a full forensic investigation should be initiated immediately.

TrendPulse
Aug 7th, 2026
Framework data breach exposes customer information via vendor.

Framework data breach exposes customer information via vendor. technology TrendPulse AI Analysis This article covers technology trends, sourced from TechCrunch. Its AI system has analyzed the key points and extracted the most relevant insights for decision-makers. Below is the structured breakdown of the original content. Quick summary. * Modular laptop manufacturer Framework has confirmed a data breach affecting its entire customer base, resulting in the theft of names, email addresses, phone numbers, and physical addresses. * The incident originated from a supply chain attack on Metabase, a business intelligence provider, which suffered a zero-day exploit that allowed unauthorized access to cloud-hosted databases. * While personal contact information was compromised, the company confirmed that no customer payment data or financial records were accessed during the breach. Key details. Framework, known for its focus on repairability and modular hardware, recently alerted its user base to a significant security incident. According to company spokesperson Eric Schumacher, the breach impacted all customers, though the firm has not disclosed the exact number of individuals affected. While the company occupies a niche segment of the PC market, industry estimates suggest the user base spans hundreds of thousands of device owners. The breach was not a direct attack on Framework's own infrastructure but rather a downstream consequence of a security failure at Metabase. Metabase publicly disclosed that attackers utilized an unknown security flaw - a zero-day vulnerability - to bypass protections and gain access to customer databases stored on their cloud servers. Framework's internal investigation confirmed that while their cloud instance was accessed, sensitive financial data remained secure. The hackers exploited the bug to give them the ability to access customers' databases stored on Metabase's cloud servers. Why this matters. This incident highlights the growing fragility of the modern software supply chain. Even companies with strong internal security protocols remain vulnerable to the weaknesses of their third-party vendors. For executives and IT decision-makers, this serves as a stark reminder that vendor risk management is no longer a secondary concern but a critical component of an organization's overall cybersecurity posture. As businesses increasingly rely on specialized SaaS tools for business intelligence and data analytics, the attack surface expands significantly. Organizations must prioritize rigorous vendor auditing and demand transparency regarding the security practices of their partners. Moving forward, companies should adopt a 'zero-trust' approach to third-party integrations, ensuring that even if a vendor is compromised, the blast radius of the stolen data is strictly limited. The bottom line. The Framework breach underscores the urgent need for companies to treat third-party vendor security as a core extension of their own internal risk management strategy. This article has been processed and analyzed by TrendPulse AI for informational purposes. Content may have been summarized or restructured for clarity.

Recently Posted Jobs

Sign up to get curated job recommendations

There are no jobs for Framework right now.

Find jobs on Simplify and start your career today

We update Framework's jobs every few hours, so check again soon! Browse all jobs →