CVE-2025-64481 is an open redirect vulnerability affecting Datasette versions 0.65.1 and below, and 1.0a0 through 1.0a19. This flaw allows a specially crafted URL with a double slash to redirect users to an arbitrary external site. The vulnerability is rated as Low severity with a CVSS score of 2.7, indicating a low potential impact primarily on integrity (VI:L) and requiring no user interaction for exploitation (UI:N). There is currently no evidence of active exploitation, public exploit code, or significant community discussion surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| Simonw | Datasette | < 0.65.2, >= 1.0a0, < 1.0a20CNA affected |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.