Vulnerabilities

ID
Packages
Summary
Published
arrow_upward
Attributes
PYSEC-2025-73
  • PyPI/datasette
See record for full details 07 Nov 2025
  • No fix available
  • Severity - 2.7 (Low)
GHSA-w832-gg5g-x44m
  • PyPI/datasette
Open redirect endpoint in Datasette 06 Nov 2025
  • Fix available
  • Severity - 2.7 (Low)
PYSEC-2023-154
  • PyPI/datasette
  • github.com/simonw/datasette
See record for full details 25 Aug 2023
  • Fix available
  • Severity - 5.3 (Medium)
GHSA-7ch3-7pp7-7cpq
  • PyPI/datasette
Datasette 1.0 alpha series leaks names of databases and tables to unauthenticated users 22 Aug 2023
  • Fix available
  • Severity - 5.3 (Medium)
PYSEC-2021-89
  • PyPI/datasette
See record for full details 07 Jun 2021
  • Fix available
GHSA-xw7c-jx9m-xh5g
  • PyPI/datasette
Reflected cross-site scripting issue in Datasette 07 Jun 2021
  • Fix available
  • Severity - 5.3 (Medium)
GHSA-74hv-qjjq-h7g5
  • PyPI/datasette-graphql
datasette-graphql leaks details of the schema of private database files 24 Nov 2020
  • Fix available
GHSA-mjcr-rqjg-rhg3
  • PyPI/datasette-indieauth
Implementation trusts the "me" field returned by the authorization server without verifying it 24 Nov 2020
  • Fix available
GHSA-q6j3-c4wc-63vw
  • PyPI/datasette
CSRF tokens leaked in URL by canned query form 11 Aug 2020
  • Fix available
  • Severity - 4.3 (Medium)