PyPI: flask-appbuilder

CVE-2024-45314

Safety vulnerability ID: SFTY-20240904-35920

Safety legacy ID: pyup.io-73129

In flask-appbuilder affected versions, the authentication database login form's default cache directives allow browsers to locally store sensitive data. This poses a security risk, particularly in environments where computer resources are shared. The latest release contains a patch addressing this issue. If upgrading is not feasible, users can mitigate the vulnerability by configuring their web server to send specific HTTP headers for the /login endpoint, following the instructions provided in the GitHub Security Advisory.

Created at: Jul 5, 2026Updated at: Jul 5, 2026

Overview

Flask-AppBuilder's login form allows browser to cache sensitive fields

Advisory

In flask-appbuilder affected versions, the authentication database login form's default cache directives allow browsers to locally store sensitive data. This poses a security risk, particularly in environments where computer resources are shared. The latest release contains a patch addressing this issue. If upgrading is not feasible, users can mitigate the vulnerability by configuring their web server to send specific HTTP headers for the /login endpoint, following the instructions provided in the GitHub Security Advisory.

Affected Package

Affecting flask-appbuilder package, versions
<4.5.1

Also affects

---

How to Fix

Upgrade
flask-appbuilder
to
4.5.1
or higher.

Mitigation and Workarounds

---

Vulnerable Functions

Functions linked to known vulnerabilities.

Vulnerable function data is available for Enterprise customers

Book a call with us to see Safety in action.

Safety

Verified by Safety

Our Cybersecurity Intelligence Team reviewed this vulnerability. We combine public data with our own research to find issues not yet reported to public sources.

Learn more