VDB
Sign up
LOW3.6

PYSEC-2026-1382

Flask-AppBuilder's login form allows browser to cache sensitive fields

Quick fix

PYSEC-2026-1382 — flask-appbuilder: upgrade to the fixed version with the command below.

pip install --upgrade 'flask-appbuilder>=4.5.1'

Details

### Impact Auth DB login form default cache directives allows browser to locally store sensitive data. This can be an issue on environments using shared computer resources.

### Patches Upgrade flask-appbuilder to version 4.5.1

### Workarounds If upgrading is not possible configure your web server to send the following HTTP headers for /login: "Cache-Control": "no-store, no-cache, must-revalidate, max-age=0" "Pragma": "no-cache" "Expires": "0"

Are you affected?

Enter the version of the package you're using.

Affected packages

PyPI/flask-appbuilder
Introduced in: 0Fixed in: 4.5.1
Fixpip install --upgrade 'flask-appbuilder>=4.5.1'

References