{"id":"PYSEC-2026-1381","summary":"Flask-AppBuilder's OAuth login page subject to Cross Site Scripting (XSS)","details":"### Impact\nA Cross-Site Scripting (XSS) vulnerability has been discovered on the OAuth login page. An attacker could trick a user to follow a specially crafted URL to the OAuth login page. This URL could inject and execute malicious javascript code that would get executed on the user's browser.\n\nImpacted versions:\nFlask-AppBuilder version 4.1.4 up to and including 4.2.0\n\n### Patches\nThis issue was introduced on 4.1.4 and patched on 4.2.1, user's should upgrade to 4.2.1 or newer versions.","aliases":["CVE-2024-27083","GHSA-fqxj-46wg-9v84"],"modified":"2026-07-07T17:47:37.826047043Z","published":"2026-07-07T11:45:33.452545Z","references":[{"type":"WEB","url":"https://github.com/dpgaspar/Flask-AppBuilder/security/advisories/GHSA-fqxj-46wg-9v84"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-27083"},{"type":"WEB","url":"https://github.com/dpgaspar/Flask-AppBuilder/commit/3d17741886e4b3c384d0570de69689e4117aa812"},{"type":"PACKAGE","url":"https://github.com/dpgaspar/Flask-AppBuilder"},{"type":"PACKAGE","url":"https://pypi.org/project/flask-appbuilder"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-fqxj-46wg-9v84"}],"affected":[{"package":{"name":"flask-appbuilder","ecosystem":"PyPI","purl":"pkg:pypi/flask-appbuilder"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"4.1.4"},{"fixed":"4.2.1"}]}],"versions":["4.1.4","4.1.5","4.1.5rc1","4.1.6","4.1.6rc1","4.1.7rc1","4.2.0","4.2.0rc1","4.2.1rc1"],"database_specific":{"source":"https://github.com/pypa/advisory-database/blob/main/vulns/flask-appbuilder/PYSEC-2026-1381.yaml"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N"}]}