Executive brief
Datasette, a tool for exploring and publishing data, contains a vulnerability that allows for open redirects. An attacker could craft a link that appears to belong to a trusted Datasette instance but instead redirects the user to a malicious external website. This can be used in phishing campaigns to trick users into providing credentials or downloading malware on a site they believe is legitimate.
Technical details
An open redirect vulnerability (CWE-601) exists in Datasette versions prior to 0.65.2 and 1.0a21. The application incorrectly handles URL paths starting with double slashes (e.g., //example.com/path/), which triggers a redirect to the specified external domain. This occurs when a trailing slash is present in the request. Attackers can exploit this by distributing malicious links that leverage the reputation of a trusted Datasette deployment to facilitate phishing or social engineering attacks. The issue is resolved in versions 0.65.2 and 1.0a21; a workaround involves configuring a reverse proxy to normalize double slashes in incoming requests.
Affected products
- simonw datasette < 0.65.2, >= 1.0a0, < 1.0a21
Timeline
- 2025-11-05: disclosed
- 2025-11-06: advisory: GitHub Advisory published
- 2025-11-07: patched: NVD publication date
References
- https://api.github.com/users/jamesjefferies
- https://github.com/jamesjefferies
- https://api.github.com/users/jamesjefferies/gists%7B/gist_id%7D
- https://api.github.com/users/jamesjefferies/repos
- https://avatars.githubusercontent.com/u/1698465?v=4
- https://api.github.com/users/jamesjefferies/events%7B/privacy%7D