PyPI: flask-appbuilder

CVE-2024-27083

Safety vulnerability ID: SFTY-20240229-21059

Safety legacy ID: pyup.io-66967

Flask-AppBuilder is an application development framework, built on top of Flask. A Cross-Site Scripting (XSS) vulnerability has been discovered on the OAuth login page. An attacker could trick a user to follow a specially crafted URL to the OAuth login page. This URL could inject and execute malicious javascript code that would get executed on the user's browser. This issue was introduced on 4.1.4 and patched on 4.2.1. See CVE-2024-27083.

Created at: Jul 5, 2026Updated at: Jul 5, 2026

Overview

Flask-AppBuilder's OAuth login page subject to Cross Site Scripting (XSS)

Advisory

Flask-AppBuilder is an application development framework, built on top of Flask. A Cross-Site Scripting (XSS) vulnerability has been discovered on the OAuth login page. An attacker could trick a user to follow a specially crafted URL to the OAuth login page. This URL could inject and execute malicious javascript code that would get executed on the user's browser. This issue was introduced on 4.1.4 and patched on 4.2.1. See CVE-2024-27083.

Affected Package

Affecting flask-appbuilder package, versions
>=4.1.4,<4.2.1

Also affects

---

How to Fix

Upgrade
flask-appbuilder
to
4.2.1
or higher.

Mitigation and Workarounds

---

Vulnerable Functions

Functions linked to known vulnerabilities.

Vulnerable function data is available for Enterprise customers

Book a call with us to see Safety in action.

Safety

Verified by Safety

Our Cybersecurity Intelligence Team reviewed this vulnerability. We combine public data with our own research to find issues not yet reported to public sources.

Learn more