PyPi: Confidant

PVE-2025-75464

Safety vulnerability ID: 75464

This vulnerability was reviewed by experts

The information on this page was manually curated by our Cybersecurity Intelligence Team.

Created at Feb 14, 2025 Updated at Feb 15, 2025

Advisory

Confidant fixes potential XSS from API call by enforcing strict HTTP response headers.

[This advisory has been limited. Please create a free account to view the full advisory.]

Affected package

confidant

Latest version: 7.0.0

DEPRECATED: A secret management system and client.

Affected versions

Fixed versions

Vulnerability changelog

* XSS security fix / enhancement for Flask API response

[This text has been limited. Please create a free account to view the full text.]

Resources