PyPI: flask-appbuilder

CVE-2025-58065

Safety vulnerability ID: SFTY-20250911-95961

Safety legacy ID: pyup.io-79598

Affected versions of the flask-appbuilder package are vulnerable to Improper Authentication due to the password-reset endpoint remaining registered and reachable when non-AUTH_DB authentication (e.g., OAuth or LDAP) is enabled. The framework continued to expose password-reset routes (such as ResetMyPasswordView) even though the link was hidden in the UI, allowing local password/JWT flows to proceed without checking the external identity provider’s disabled state. An attacker with an enabled account in Flask-AppBuilder can directly invoke the reset-my-password URL while the deployment uses OAuth/LDAP and set a new password to mint JWT tokens, effectively retaining access even if they were disabled on the external provider.

Created at: Jul 5, 2026Updated at: Jul 5, 2026

Overview

Flask App Builder has an Authentication Bypass vulnerability when using non AUTH_DB methods

Advisory

Affected versions of the flask-appbuilder package are vulnerable to Improper Authentication due to the password-reset endpoint remaining registered and reachable when non-AUTH_DB authentication (e.g., OAuth or LDAP) is enabled. The framework continued to expose password-reset routes (such as ResetMyPasswordView) even though the link was hidden in the UI, allowing local password/JWT flows to proceed without checking the external identity provider’s disabled state. An attacker with an enabled account in Flask-AppBuilder can directly invoke the reset-my-password URL while the deployment uses OAuth/LDAP and set a new password to mint JWT tokens, effectively retaining access even if they were disabled on the external provider.

Affected Package

Affecting flask-appbuilder package, versions
<4.8.1

Also affects

---

How to Fix

Upgrade
flask-appbuilder
to
4.8.1
or higher.

Mitigation and Workarounds

---

Vulnerable Functions

Functions linked to known vulnerabilities.

Vulnerable function data is available for Enterprise customers

Book a call with us to see Safety in action.

Safety

Verified by Safety

Our Cybersecurity Intelligence Team reviewed this vulnerability. We combine public data with our own research to find issues not yet reported to public sources.

Learn more