PyPI: flask-appbuilder
CVE-2025-32962
Safety vulnerability ID: SFTY-20250516-05507
Safety legacy ID: pyup.io-77317
Affected versions of the `Flask-AppBuilder` package are vulnerable to Open Redirect due to improper validation of the Host header in HTTP requests. The `redirect` function fails to verify that the Host header matches a trusted domain, allowing arbitrary redirection. An attacker can exploit this by crafting a request with a manipulated Host header, redirecting users to a malicious site without their knowledge or consent.
Overview
Flask-AppBuilder open redirect vulnerability using HTTP host injection
Advisory
Affected versions of the `Flask-AppBuilder` package are vulnerable to Open Redirect due to improper validation of the Host header in HTTP requests. The `redirect` function fails to verify that the Host header matches a trusted domain, allowing arbitrary redirection. An attacker can exploit this by crafting a request with a manipulated Host header, redirecting users to a malicious site without their knowledge or consent.
How to Fix
Mitigation and Workarounds
---
Vulnerable Functions
Functions linked to known vulnerabilities.
References
- https://getsafety.com/vulnerabilities/SFTY-20250516-05507/CVE-2025-32962
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-32962
- https://github.com/advisories/GHSA-99pm-ch96-ccp2
- https://github.com/dpgaspar/Flask-AppBuilder/commit/32eedbbb5cb483a3e782c5f2732de4a6a650d9b6
- https://github.com/dpgaspar/Flask-AppBuilder/security/advisories/GHSA-99pm-ch96-ccp2
- https://nvd.nist.gov/vuln/detail/CVE-2025-32962
- https://github.com/dpgaspar/Flask-AppBuilder/commit/32eedbbb5cb483a3e782c5f2732de4a6a650d9b6
- https://github.com/advisories/GHSA-99pm-ch96-ccp2
Verified by Safety
Our Cybersecurity Intelligence Team reviewed this vulnerability. We combine public data with our own research to find issues not yet reported to public sources.
Learn more
