VDB
Sign up
MEDIUM4.3

PYSEC-2026-1379

Flask-AppBuilder open redirect vulnerability using HTTP host injection

Quick fix

PYSEC-2026-1379 — flask-appbuilder: upgrade to the fixed version with the command below.

pip install --upgrade 'flask-appbuilder>=4.6.2'

Details

### Impact Flask-AppBuilder prior to 4.6.2 would allow for a malicious unauthenticated actor to perform an open redirect by manipulating the Host header in HTTP requests. ### Patches Flask-AppBuilder 4.6.2 introduced the `FAB_SAFE_REDIRECT_HOSTS` configuration variable, which allows administrators to explicitly define which domains are considered safe for redirection.

Examples: ``` FAB_SAFE_REDIRECT_HOSTS = ["yourdomain.com", "sub.yourdomain.com", "*.yourcompany.com"] ```

### Workarounds Use a Reverse Proxy to Enforce Trusted Host Headers

### References _Are there any links users can visit to find out more?_

Are you affected?

Enter the version of the package you're using.

Affected packages

PyPI/flask-appbuilder
Introduced in: 0Fixed in: 4.6.2
Fixpip install --upgrade 'flask-appbuilder>=4.6.2'

References