Safety vulnerability ID: 72731
The information on this page was manually curated by our Cybersecurity Intelligence Team.
A vulnerability in corydolphin/flask-cors allows the Access-Control-Allow-Private-Network CORS header to be set to true by default, without any configuration option. This behaviour can expose private network resources to unauthorized external access, leading to significant security risks such as data breaches, access to sensitive information, and potential network intrusions.
Latest version: 5.0.0
A Flask extension adding a decorator for CORS support
This vulnerability has no description
Scan your Python project for dependency vulnerabilities in two minutes
Scan your application