Open Redirect Vulnerability in Flask-AppBuilder by DPGaspar
CVE-2025-32962
What is CVE-2025-32962?
An open redirect vulnerability exists in Flask-AppBuilder, allowing an unauthenticated attacker to manipulate the Host header in HTTP requests. This can lead to redirection to untrusted domains, potentially compromising user data or leading them to phishing sites. Version 4.6.2 of Flask-AppBuilder introduces a configuration option named FAB_SAFE_REDIRECT_HOSTS, enabling administrators to specify safe domains for redirection. It's advised to implement this feature to mitigate the risk, and as a temporary measure, using a reverse proxy to control host headers is recommended.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Flask-AppBuilder < 4.6.2
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved
