Simon Willison 11/6/2025

Open redirect endpoint in Datasette prior to 0.65.2 and 1.0a21

Read Original

GitHub security advisory detailing an open redirect vulnerability in Datasette versions prior to 0.65.2 and 1.0a21. The fix by James Jefferies is included in these releases, which also add Python 3.14 support, a Cloud Run deployment fix, and new features for inspecting headers and bypassing permission checks in the internal client.

Open redirect endpoint in Datasette prior to 0.65.2 and 1.0a21

Comments

No comments yet

Be the first to share your thoughts!

Browser Extension

Get instant access to AllDevBlogs from your browser