{"id":"GHSA-cg8c-gc2j-2wf7","summary":"Flask-Security vulnerable to Open Redirect","details":"This affects all versions of package Flask-Security. When using the `get_post_logout_redirect` and `get_post_login_redirect` functions, it is possible to bypass URL validation and redirect a user to an arbitrary URL by providing multiple back slashes such as `\\\\\\evil.com/path`. This vulnerability is only exploitable if an alternative WSGI server other than Werkzeug is used, or the default behaviour of Werkzeug is modified using `'autocorrect_location_header=False`.\n\n**Note:** Flask-Security is not maintained anymore.","aliases":["CVE-2021-23385","PYSEC-2026-809"],"modified":"2026-07-07T11:56:48.424362779Z","published":"2022-10-07T07:29:01Z","database_specific":{"github_reviewed":true,"github_reviewed_at":"2022-10-07T07:29:01Z","nvd_published_at":"2022-08-02T14:15:00Z","cwe_ids":["CWE-601"],"severity":"MODERATE"},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2021-23385"},{"type":"PACKAGE","url":"https://github.com/mattupstate/flask-security"},{"type":"WEB","url":"https://security.snyk.io/vuln/SNYK-PYTHON-FLASKSECURITY-1293234"},{"type":"WEB","url":"https://snyk.io/blog/url-confusion-vulnerabilities"}],"affected":[{"package":{"name":"flask-security","ecosystem":"PyPI","purl":"pkg:pypi/flask-security"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"last_affected":"3.0.0"}]}],"versions":["1.2.0","1.2.1","1.2.2","1.2.3","1.5.0","1.5.1","1.5.2","1.5.3","1.5.4","1.6.0","1.6.1","1.6.2","1.6.3","1.6.4","1.6.5","1.6.6","1.6.7","1.6.8","1.6.9","1.7.0","1.7.1","1.7.2","1.7.3","1.7.4","1.7.5","3.0.0"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/10/GHSA-cg8c-gc2j-2wf7/GHSA-cg8c-gc2j-2wf7.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"}]}