NONE · 0

CVE-2025-64481

Datasette is an open source multi-tool for exploring and publishing data. In versions 0.65.1 and below and 1.0a0 through 1.0a19, deployed instances of Datasette include an open redirect vulnerability....

Vulnerability Description

Datasette is an open source multi-tool for exploring and publishing data. In versions 0.65.1 and below and 1.0a0 through 1.0a19, deployed instances of Datasette include an open redirect vulnerability. Hits to the path //example.com/foo/bar/ (the trailing slash is required) will redirect the user to https://example.com/foo/bar. This problem has been patched in both Datasette 0.65.2 and 1.0a21. To workaround this issue, if Datasette is running behind a proxy, that proxy could be configured to replace // with / in incoming request URLs.

Related Weaknesses (CWE)

References

FAQ

What is CVE-2025-64481?

CVE-2025-64481 is a documented vulnerability. Datasette is an open source multi-tool for exploring and publishing data. In versions 0.65.1 and below and 1.0a0 through 1.0a19, deployed instances of Datasette include an open redirect vulnerability....

How severe is CVE-2025-64481?

CVSS scoring is not yet available for CVE-2025-64481. Check NVD for updates.

Is there a patch for CVE-2025-64481?

Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.