VDB
CVE-2025-32962
CVE-2025-32962
PUBLISHED
CVSS 4.300000190734863 MEDIUM
Flask-AppBuilder is an application development framework built on top of Flask. Versions prior to 4.6.2 would allow for a malicious unauthenticated actor to perform an open redirect by manipulating the Host header in HTTP requests. Flask-AppBuilder 4.6.2 introduced the `FAB_SAFE_REDIRECT_HOSTS` configuration variable, which allows administrators to explicitly define which domains are considered safe for redirection. As a workaround, use a reverse proxy to enforce trusted host headers.
EPSS 0.20% · 41.7th percentile
Risk Scores
CVSS v3.1
4.300000190734863
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N
EPSS Score
0.20%
41.7th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| PyPI | flask-appbuilder | 0 |
| dpgaspar | flask-appbuilder | 0 |
| dpgaspar | Flask-AppBuilder | < 4.6.2 |
Timeline
- Jan 21, 1970 Security Advisory
- May 16, 2025 CVE Published
- May 16, 2025 Coalition ESS Score
- May 16, 2025 PoC Published
- May 17, 2025 EPSS Score
- May 28, 2025 EPSS Score
- Jun 9, 2025 EPSS Score
- Jun 20, 2025 EPSS Score
- Jul 1, 2025 EPSS Score
- Jul 12, 2025 EPSS Score
- Jul 24, 2025 EPSS Score
- Aug 4, 2025 EPSS Score