docassemble@1.4.54 vulnerabilities

The namespace package for the docassemble system.

Direct Vulnerabilities

Known vulnerabilities in the docassemble package. This does not include vulnerabilities belonging to this package’s dependencies.

Automatically find and fix vulnerabilities affecting your projects. Snyk scans for vulnerabilities and provides fixes for free.
Fix for free
Vulnerability Vulnerable Version
  • M
Open Redirect

docassemble is an A free, open-source expert system for guided interviews and document assembly, based on Python, YAML, and Markdown.

Affected versions of this package are vulnerable to Open Redirect due to improper validation of user-supplied input. An attacker can redirect users to an untrusted page by manipulating the URL parameters to point to a malicious site.

How to fix Open Redirect?

Upgrade docassemble to version 1.4.97 or higher.

[,1.4.97)