PT-2024-6446 · Pypi+4 · Flask-Cors+4

Published

2024-05-11

·

Updated

2025-11-13

·

CVE-2024-6221

CVSS v4.0

8.7

High

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions corydolphin/flask-cors version 4.0.1
Description A vulnerability in corydolphin/flask-cors allows the Access-Control-Allow-Private-Network CORS header to be set to true by default, without any configuration option. This behavior can expose private network resources to unauthorized external access, leading to significant security risks such as data breaches, unauthorized access to sensitive information, and potential network intrusions.
Recommendations For corydolphin/flask-cors version 4.0.1, upgrade to version 4.0.2 or later to secure your setup. As a temporary workaround, consider disabling the Access-Control-Allow-Private-Network CORS header until a patch is available. Restrict access to private network resources to minimize the risk of exploitation. Avoid using the default configuration option for the Access-Control-Allow-Private-Network CORS header in the affected API endpoint until the issue is resolved.

Exploit

Fix

Improper Access Control

Weakness Enumeration

Related Identifiers

BDU:2024-07531
CVE-2024-6221
GHSA-HXWH-JPP2-84PM
MGASA-2025-0286
OESA-2024-2198
PYSEC-2024-260
PYSEC-2024-71
USN-7612-1

Affected Products

Debian
Linuxmint
Red Os
Ubuntu
Flask-Cors