MEDIUM6.1
PYSEC-2026-635
Open Redirect in Flask-AppBuilder
Quick fix
PYSEC-2026-635 — flask-appbuilder: upgrade to the fixed version with the command below.
pip install --upgrade 'flask-appbuilder>=3.4.5'Details
Flask-AppBuilder is an application development framework built on top of Flask. Versions prior to 3.4.5 contain an open redirect vulnerability when using the database authentication login page. There are no known workarounds. Users are recommended to upgrade to version 3.4.5 or later.
### For more information If you have any questions or comments about this advisory: * Open an issue in [Flask-AppBuilder](https://github.com/dpgaspar/Flask-AppBuilder)
Are you affected?
Enter the version of the package you're using.
Affected packages
PyPI/flask-appbuilder
Introduced in:
0Fixed in: 3.4.5Fix
pip install --upgrade 'flask-appbuilder>=3.4.5'References
- https://github.com/dpgaspar/Flask-AppBuilder/security/advisories/GHSA-2ccw-7px8-vmpf[WEB]
- https://nvd.nist.gov/vuln/detail/CVE-2022-24776[ADVISORY]
- https://github.com/dpgaspar/Flask-AppBuilder/pull/1804[WEB]
- https://github.com/dpgaspar/Flask-AppBuilder/pull/1804/commits/5214d975ebad2ff32057443d2cc20fef1c04d0ea[WEB]
- https://github.com/dpgaspar/Flask-AppBuilder[PACKAGE]
- https://github.com/dpgaspar/Flask-AppBuilder/releases/tag/v3.4.5[WEB]
- https://pypi.org/project/flask-appbuilder[PACKAGE]
- https://github.com/advisories/GHSA-2ccw-7px8-vmpf[ADVISORY]