PYSEC-2026-1379
Flask-AppBuilder open redirect vulnerability using HTTP host injection
Quick fix
PYSEC-2026-1379 — flask-appbuilder: upgrade to the fixed version with the command below.
pip install --upgrade 'flask-appbuilder>=4.6.2'Details
### Impact Flask-AppBuilder prior to 4.6.2 would allow for a malicious unauthenticated actor to perform an open redirect by manipulating the Host header in HTTP requests. ### Patches Flask-AppBuilder 4.6.2 introduced the `FAB_SAFE_REDIRECT_HOSTS` configuration variable, which allows administrators to explicitly define which domains are considered safe for redirection.
Examples: ``` FAB_SAFE_REDIRECT_HOSTS = ["yourdomain.com", "sub.yourdomain.com", "*.yourcompany.com"] ```
### Workarounds Use a Reverse Proxy to Enforce Trusted Host Headers
### References _Are there any links users can visit to find out more?_
Are you affected?
Enter the version of the package you're using.
Affected packages
0Fixed in: 4.6.2pip install --upgrade 'flask-appbuilder>=4.6.2'References
- https://github.com/dpgaspar/Flask-AppBuilder/security/advisories/GHSA-99pm-ch96-ccp2[WEB]
- https://nvd.nist.gov/vuln/detail/CVE-2025-32962[ADVISORY]
- https://github.com/dpgaspar/Flask-AppBuilder/commit/32eedbbb5cb483a3e782c5f2732de4a6a650d9b6[WEB]
- https://github.com/dpgaspar/Flask-AppBuilder[PACKAGE]
- https://pypi.org/project/flask-appbuilder[PACKAGE]
- https://github.com/advisories/GHSA-99pm-ch96-ccp2[ADVISORY]