Unrated severityNVD Advisory· Published Aug 19, 2025· Updated Aug 19, 2025
flaskBlog allows arbitrary privilege escalation
CVE-2025-55736
Description
flaskBlog is a blog app built with Flask. In 2.8.0 and earlier, an arbitrary user can change his role to "admin", giving its relative privileges (e.g. delete users, posts, comments etc.). The problem is in the routes/adminPanelUsers file.
Affected products
2- DogukanUrker/FlaskBlogv5Range: <= 2.8.0
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1- github.com/DogukanUrker/FlaskBlog/security/advisories/GHSA-6q83-vfmq-wf72mitrex_refsource_CONFIRM
News mentions
0No linked articles in our index yet.