LOW3.6
PYSEC-2026-1382
Flask-AppBuilder's login form allows browser to cache sensitive fields
Quick fix
PYSEC-2026-1382 — flask-appbuilder: upgrade to the fixed version with the command below.
pip install --upgrade 'flask-appbuilder>=4.5.1'Details
### Impact Auth DB login form default cache directives allows browser to locally store sensitive data. This can be an issue on environments using shared computer resources.
### Patches Upgrade flask-appbuilder to version 4.5.1
### Workarounds If upgrading is not possible configure your web server to send the following HTTP headers for /login: "Cache-Control": "no-store, no-cache, must-revalidate, max-age=0" "Pragma": "no-cache" "Expires": "0"
Are you affected?
Enter the version of the package you're using.
Affected packages
PyPI/flask-appbuilder
Introduced in:
0Fixed in: 4.5.1Fix
pip install --upgrade 'flask-appbuilder>=4.5.1'References
- https://github.com/dpgaspar/Flask-AppBuilder/security/advisories/GHSA-fw5r-6m3x-rh7p[WEB]
- https://nvd.nist.gov/vuln/detail/CVE-2024-45314[ADVISORY]
- https://github.com/dpgaspar/Flask-AppBuilder/commit/3030e881d2e44f4021764e18e489fe940a9b3636[WEB]
- https://github.com/dpgaspar/Flask-AppBuilder[PACKAGE]
- https://pypi.org/project/flask-appbuilder[PACKAGE]
- https://github.com/advisories/GHSA-fw5r-6m3x-rh7p[ADVISORY]