flask-oidc is vulnerable to Open Redirect
75
High Risk
Affected versions of the package are vulnerable to open redirect attacks due to improper handling of malformed login and logout URLs. An attacker could craft a specially constructed URL that redirects users to an external, potentially malicious site after login or logout. This could be used for phishing, credential theft, or other social engineering attacks by abusing the trust users place in the original application.
You are affected if you are using a version that falls within the vulnerable range.
flask-oidc is vulnerable to Open Redirect in versions 2.0.0 - 2.3.1.
Upgrade the flask-oidc library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant