Unrated severityNVD Advisory· Published Aug 19, 2025· Updated Aug 19, 2025
flaskBlog arbitrary comment delete
CVE-2025-55737
Description
flaskBlog is a blog app built with Flask. In 2.8.0 and earlier, when deleting a comment, there's no validation of the ownership of the comment. Every user can delete an arbitrary comment of another user on every post, by simply intercepting the delete request and changing the commentID. The code that causes the problem is in routes/post.py.
Affected products
2- DogukanUrker/FlaskBlogv5Range: <= 2.8.0
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1- github.com/DogukanUrker/FlaskBlog/security/advisories/GHSA-6hp9-jv2f-88wrmitrex_refsource_CONFIRM
News mentions
0No linked articles in our index yet.