PT-2025-21650 · Unknown · Flask-Appbuilder
Mar0N0
·
Published
2025-05-16
·
Updated
2025-12-01
·
CVE-2025-32962
CVSS v3.1
6.1
Medium
| AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions:
Flask-AppBuilder versions prior to 4.6.2
Description:
The issue allows a malicious unauthenticated actor to perform an open redirect by manipulating the Host header in HTTP requests. Flask-AppBuilder 4.6.2 introduced the
FAB SAFE REDIRECT HOSTS configuration variable, which allows administrators to explicitly define which domains are considered safe for redirection.Recommendations:
For versions prior to 4.6.2, use a reverse proxy to enforce trusted host headers as a workaround.
Update to version 4.6.2 or later, which introduces the
FAB SAFE REDIRECT HOSTS configuration variable to define safe domains for redirection.Exploit
Fix
Open Redirect
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Flask-Appbuilder