{"id":"CVE-2025-64481","summary":"Open redirect endpoint in Datasette","details":"Datasette is an open source multi-tool for exploring and publishing data. In versions 0.65.1 and below and 1.0a0 through 1.0a19, deployed instances of Datasette include an open redirect vulnerability. Hits to the path //example.com/foo/bar/ (the trailing slash is required) will redirect the user to https://example.com/foo/bar. This problem has been patched in both Datasette 0.65.2 and 1.0a21. To workaround this issue, if Datasette is running behind a proxy, that proxy could be configured to replace // with / in incoming request URLs.","aliases":["GHSA-w832-gg5g-x44m","PYSEC-2025-73"],"modified":"2026-08-12T03:51:44.895141504Z","published":"2025-11-07T20:35:39.827Z","database_specific":{"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/64xxx/CVE-2025-64481.json","cna_assigner":"GitHub_M","cwe_ids":["CWE-601"]},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/64xxx/CVE-2025-64481.json"},{"type":"ADVISORY","url":"https://github.com/simonw/datasette/security/advisories/GHSA-w832-gg5g-x44m"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-64481"},{"type":"REPORT","url":"https://github.com/simonw/datasette/issues/2429"},{"type":"FIX","url":"https://github.com/simonw/datasette/commit/f257ca6edb64848c3b04b54d41e347c54fe57c05"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/simonw/datasette","events":[{"introduced":"4a0bd960e9763623dae6a13c8af3810c4ce9fb0a"},{"fixed":"6f7f4c7d89b37187667441ce9df583f6dbbe2977"},{"fixed":"f257ca6edb64848c3b04b54d41e347c54fe57c05"}],"database_specific":{"source":["DESCRIPTION","REFERENCES"],"extracted_events":[{"introduced":"1.0a0"},{"fixed":"1.0a19"}]}}],"versions":["1.0a20","1.0a19","1.0a18","1.0a17","1.0a16","1.0a15","1.0a14","1.0a13","1.0a12","1.0a11","1.0a10","1.0a9","1.0a8","1.0a6","1.0a5","1.0a4","1.0a3","1.0a2","1.0a1","1.0a0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-64481.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:U"}]}