Medium severity5.4GHSA Advisory· Published Jul 5, 2021· Updated Jun 17, 2026
CVE-2021-23401
CVE-2021-23401
Description
This affects all versions of package Flask-User. When using the make_safe_url function, it is possible to bypass URL validation and redirect a user to an arbitrary URL by providing multiple back slashes such as /////evil.com/path or \\\evil.com/path. This vulnerability is only exploitable if an alternative WSGI server other than Werkzeug is used, or the default behaviour of Werkzeug is modified using 'autocorrect_location_header=False.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
Flask-UserPyPI | <= 1.0.2.2 | — |
Affected products
3- Range: <= 1.0.2.2
- cpe:2.3:a:flask-user_project:flask-user:*:*:*:*:*:*:*:*
Patches
Vulnerability mechanics
References
5- github.com/lingthio/Flask-User/blob/master/flask_user/user_manager__utils.pynvdExploitThird Party AdvisoryWEB
- github.com/advisories/GHSA-4298-89hc-6rfvghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2021-23401ghsaADVISORY
- snyk.io/vuln/SNYK-PYTHON-FLASKUSER-1293188nvdThird Party AdvisoryWEB
- github.com/pypa/advisory-database/tree/main/vulns/flask-user/PYSEC-2021-337.yamlghsaWEB
News mentions
0No linked articles in our index yet.