Junglewise Threat Intelligence

CVE-2025-64481: Datasette open redirect vulnerability

CVE-2025-64481 · Severity: medium · CVSS 4 · Published 2025-11-06

Technologies: Simonw Datasette. Vendors: PyPI.

Executive brief

Datasette, a tool for exploring and publishing data, contains a vulnerability that allows for open redirects. An attacker could craft a link that appears to belong to a trusted Datasette instance but instead redirects the user to a malicious external website. This can be used in phishing campaigns to trick users into providing credentials or downloading malware on a site they believe is legitimate.

Technical details

An open redirect vulnerability (CWE-601) exists in Datasette versions prior to 0.65.2 and 1.0a21. The application incorrectly handles URL paths starting with double slashes (e.g., //example.com/path/), which triggers a redirect to the specified external domain. This occurs when a trailing slash is present in the request. Attackers can exploit this by distributing malicious links that leverage the reputation of a trusted Datasette deployment to facilitate phishing or social engineering attacks. The issue is resolved in versions 0.65.2 and 1.0a21; a workaround involves configuring a reverse proxy to normalize double slashes in incoming requests.

Affected products

  • simonw datasette < 0.65.2, >= 1.0a0, < 1.0a21

Timeline

  • 2025-11-05: disclosed
  • 2025-11-06: advisory: GitHub Advisory published
  • 2025-11-07: patched: NVD publication date

References

Related threats