---
id: CVE-2022-43721
aliases:
  - GHSA-fcg4-pm6h-9xx2
  - BIT-superset-2022-43721
  - PYSEC-2026-781
title: Apache Superset Open Redirect vulnerability
summary: Apache Superset Open Redirect vulnerability
severity: medium
cvss: 5.4
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N'
vendor: apache-superset
product: apache-superset
ecosystem: pip
affected:
  - apache-superset <= 1.5.2
  - apache-superset
published: '2023-01-16'
updated: '2026-07-07'
source: OSV
sourceUrl: 'https://osv.dev/vulnerability/GHSA-fcg4-pm6h-9xx2'
references:
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2022-43721'
  - url: 'https://github.com/apache/superset'
  - url: 'https://lists.apache.org/thread/s6sqt5jmcv6qxtvdot1t5tpt57v439kg'
tags:
  - osv
  - pip
epss: 0.01002
epssPercentile: 0.61352
ingestedAt: '2026-07-08T18:25:48.860Z'
---

## Overview

An authenticated attacker with update datasets permission could change a dataset link to an untrusted site, users could be redirected to this site when clicking on that specific dataset. This issue affects Apache Superset version 1.5.2 and prior versions and version 2.0.0.

## Affected packages

- `apache-superset <= 1.5.2`
- `apache-superset`

## Remediation

Refer to the advisory for the patched release.
