CVE-2021-32670High· 7.2▾ TwilightReflected cross-site scripting issue in Datasette
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 39.6 · likelihood 0.2 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Jul 8.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via OSV
Last analysed / modified upstream
1.0%
The ?_trace=1 debugging feature in Datasette does not correctly escape generated HTML, resulting in a reflected cross-site scripting vulnerability.
This vulnerability is particularly relevant if your Datasette installation includes authenticated features using plugins such as datasette-auth-passwords as an attacker could use the vulnerability to access protected data.
Datasette 0.57 and 0.56.1 both include patches for this issue.
If you run Datasette behind a proxy you can workaround this issue by rejecting any incoming requests with ?_trace= or &_trace= in their query string parameters.
If you have any questions or comments about this advisory:
swillison+datasette @ gmail.comdatasette < 0.56.1Upgrade to a patched release:
datasette 0.56.1