flet is vulnerable to Session fixation
28
Low Risk
When running a Flet app in web browser mode, affected versions allow cross-tab session contamination because duplicated tabs can reuse the same session_id and improperly take over an active session connection. An attacker could exploit this by causing a victim to open or duplicate the same app session in another browser tab, leading to UI desynchronization, unintended actions being applied to the wrong tab, and denial of service of the original session through connection hijacking.
You are affected if you are using a version that falls within the vulnerable range.
flet is vulnerable to Session fixation in versions 0.80.0 - 0.85.1.
Upgrade the flet library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant