datasette
PyPI3 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting datasettepage 1 of 1
- CVE-2021-32670HIGHCVSS 7.2EG 7.2fixed in 0.56.12021-06-07
vulnerable: 0.10 ... 0.9 (92 versions)
Datasette is an open source multi-tool for exploring and publishing data. The `?_trace=1` debugging feature in Datasette does not correctly escape generated HTML, resulting in a [reflected cross-site scripting](https://owasp.org/www-commun…
- CVE-2023-40570MEDIUMCVSS 5.3EG 5.3fixed in 1.0a42023-08-25
vulnerable: 0.10 ... 1.0a9 (157 versions)
Datasette is an open source multi-tool for exploring and publishing data. This bug affects Datasette instances running a Datasette 1.0 alpha - 1.0a0, 1.0a1, 1.0a2 or 1.0a3 - in an online accessible location but with authentication enabled …
- CVE-2025-64481LOWCVSS 2.7EG 2.7fixed in 0.65.2 or 1.0a21, by version range2025-11-07
vulnerable: 1.0a0 ... 1.0a9 (21 versions)
Datasette is an open source multi-tool for exploring and publishing data. In versions 0.65.1 and below and 1.0a0 through 1.0a19, deployed instances of Datasette include an open redirect vulnerability. Hits to the path //example.com/foo/bar…
Check whether datasette is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for datasette CVEs against the assets you own.
Book a Demo →