---
id: CVE-2024-1681
aliases:
  - GHSA-84pr-m4jr-85g5
  - PYSEC-2024-271
title: flask-cors vulnerable to log injection when the log level is set to debug
summary: flask-cors vulnerable to log injection when the log level is set to debug
severity: medium
cvss: 5.3
cvssVector: 'CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N'
vendor: flask-cors
product: flask-cors
ecosystem: pip
affected:
  - flask-cors < 4.0.1
patched:
  - flask-cors 4.0.1
published: '2024-04-19'
updated: '2026-09-10'
sourceUpdated: '2026-09-10T03:50:12.410188532Z'
source: OSV
sourceUrl: 'https://osv.dev/vulnerability/GHSA-84pr-m4jr-85g5'
references:
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2024-1681'
  - url: 'https://github.com/corydolphin/flask-cors'
  - url: >-
      https://github.com/corydolphin/flask-cors/blob/40acc8092332dfed4bb54d7a4f89a6d479466de7/flask_cors/extension.py#L194
  - url: >-
      https://github.com/pypa/advisory-database/tree/main/vulns/flask-cors/PYSEC-2024-271.yaml
  - url: 'https://huntr.com/bounties/25a7a0ba-9fa2-4777-acb6-03e5539bb644'
  - url: 'https://lists.debian.org/debian-lts-announce/2025/05/msg00049.html'
tags:
  - osv
  - pip
epss: 0.00579
epssPercentile: 0.45417
ingestedAt: '2026-09-12T03:13:01.675Z'
---

## Overview

corydolphin/flask-cors is vulnerable to log injection when the log level is set to debug. An attacker can inject fake log entries into the log file by sending a specially crafted GET request containing a CRLF sequence in the request path. This vulnerability allows attackers to corrupt log files, potentially covering tracks of other attacks, confusing log post-processing tools, and forging log entries. The issue is due to improper output neutralization for logs.

## Affected packages

- `flask-cors < 4.0.1`

## Remediation

Upgrade to a patched release:

- `flask-cors 4.0.1`
