CVE-2021-32805High· 7.2▾ TwilightFlask-AppBuilder Open Redirect vulnerability
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 39.6 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Jul 8.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via OSV
Last analysed / modified upstream
0.7%
If using Flask-AppBuilder OAuth, an attacker can share a carefully crafted URL with a trusted domain for an application built with Flask-AppBuilder, this URL can redirect a user to a malicious site. This is an open redirect vulnerability
Install Flask-AppBuilder 3.2.2 or above
Filter HTTP traffic containing ?next={next-site} where the next-site domain is different from the application you are protecting
flask-appbuilder < 3.3.2Upgrade to a patched release:
flask-appbuilder 3.3.2Connected by shared product, vendor, weakness, or advisory.
CVE-2021-29621Medium· 5.3Observable Response Discrepancy in Flask-AppBuilder
CVE-2022-21659Medium· 5.3Observable Response Discrepancy in Flask-AppBuilder
CVE-2025-24023Low· 3.7Flask-AppBuilder Observable Response Discrepancy
CVE-2024-25128Critical· 9.1Flask-AppBuilder vulnerable to incorrect authentication when using auth type OpenID
CVE-2021-41265High· 8.1Improper Authentication in Flask-AppBuilder
CVE-2024-45314Low· 3.6Flask-AppBuilder's login form allows browser to cache sensitive fields