Open Redirect Vulnerability in Flask-AppBuilder by DPGaspar
CVE-2025-32962

4.3MEDIUM

Key Information:

Vendor

Dpgaspar

Vendor
CVE Published:
16 May 2025

What is CVE-2025-32962?

An open redirect vulnerability exists in Flask-AppBuilder, allowing an unauthenticated attacker to manipulate the Host header in HTTP requests. This can lead to redirection to untrusted domains, potentially compromising user data or leading them to phishing sites. Version 4.6.2 of Flask-AppBuilder introduces a configuration option named FAB_SAFE_REDIRECT_HOSTS, enabling administrators to specify safe domains for redirection. It's advised to implement this feature to mitigate the risk, and as a temporary measure, using a reverse proxy to control host headers is recommended.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

Affected Version(s)

Flask-AppBuilder < 4.6.2

References

CVSS V3.1

Score:
4.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.