CVE-2024-6839
MEDIUMflask-cors < 6.0.0 - Improper CORS Policy Enforcement via Regex Pattern Priority Mismatch
Title source: llmDescription
corydolphin/flask-cors version 4.0.1 contains an improper regex path matching vulnerability. The plugin prioritizes longer regex patterns over more specific ones when matching paths, which can lead to less restrictive CORS policies being applied to sensitive endpoints. This mismatch in regex pattern priority allows unauthorized cross-origin access to sensitive data or functionality, potentially exposing confidential information and increasing the risk of unauthorized actions by malicious actors.
References (2)
Core 2
Core References
Exploit, Third Party Advisory
https://huntr.com/bounties/403eb1fc-86f4-4820-8eba-0f3dfae9f2b4
Scores
CVSS v3
5.3
EPSS
0.0058
EPSS Percentile
69.3%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
CISA SSVC
Vulnrichment
Exploitation
poc
Automatable
no
Technical Impact
partial
Details
CWE
CWE-41
Status
published
Products (2)
flask-cors_project/flask-cors
4.0.1
pypi/flask-cors
0 - 6.0.0PyPI
Published
Mar 20, 2025
Tracked Since
Feb 18, 2026