Medium severity4.3NVD Advisory· Published May 16, 2025· Updated Jun 17, 2026
CVE-2025-32962
CVE-2025-32962
Description
Flask-AppBuilder is an application development framework built on top of Flask. Versions prior to 4.6.2 would allow for a malicious unauthenticated actor to perform an open redirect by manipulating the Host header in HTTP requests. Flask-AppBuilder 4.6.2 introduced the FAB_SAFE_REDIRECT_HOSTS configuration variable, which allows administrators to explicitly define which domains are considered safe for redirection. As a workaround, use a reverse proxy to enforce trusted host headers.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
flask-appbuilderPyPI | < 4.6.2 | 4.6.2 |
Affected products
20cpe:2.3:a:dpgaspar:flask-appbuilder:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:dpgaspar:flask-appbuilder:*:*:*:*:*:*:*:*range: <4.6.2
- (no CPE)range: < 4.6.2
- osv-coords18 versionspkg:apk/chainguard/airflow-3pkg:apk/chainguard/airflow-3-bitnami-compatpkg:apk/chainguard/airflow-3-compatpkg:apk/chainguard/airflow-3-iamguarded-compatpkg:apk/chainguard/airflow-core-2pkg:apk/chainguard/supersetpkg:apk/chainguard/superset-cipkg:apk/chainguard/superset-entrypointpkg:apk/chainguard/superset-iamguarded-compatpkg:apk/wolfi/airflow-3pkg:apk/wolfi/airflow-3-bitnami-compatpkg:apk/wolfi/airflow-3-compatpkg:apk/wolfi/airflow-3-iamguarded-compatpkg:apk/wolfi/supersetpkg:apk/wolfi/superset-cipkg:apk/wolfi/superset-entrypointpkg:apk/wolfi/superset-iamguarded-compatpkg:pypi/flask-appbuilder
< 3.0.1-r1+ 17 more
- (no CPE)range: < 3.0.1-r1
- (no CPE)range: < 3.0.1-r1
- (no CPE)range: < 3.0.1-r1
- (no CPE)range: < 3.0.1-r1
- (no CPE)range: < 2.11.2-r5
- (no CPE)range: < 4.1.2-r2
- (no CPE)range: < 4.1.2-r2
- (no CPE)range: < 4.1.2-r2
- (no CPE)range: < 4.1.2-r2
- (no CPE)range: < 3.0.1-r1
- (no CPE)range: < 3.0.1-r1
- (no CPE)range: < 3.0.1-r1
- (no CPE)range: < 3.0.1-r1
- (no CPE)range: < 4.1.2-r2
- (no CPE)range: < 4.1.2-r2
- (no CPE)range: < 4.1.2-r2
- (no CPE)range: < 4.1.2-r2
- (no CPE)range: < 4.6.2
Patches
Vulnerability mechanics
References
4News mentions
0No linked articles in our index yet.