CVE-2021-28125 is a medium-severity (CVSS 6.1) Open Redirect vulnerability in superset. EPSS puts its 30-day exploitation probability at 64.0% (99th percentile). A fix is available for superset — see the affected versions and patch details below.
Open Redirect in Apache Superset
EPSS Exploitation Probability
Probability of exploitation in the next 30 days, from FIRST.org EPSS.
How urgent is this, really
CVE-2021-28125 by exploitation likelihood (EPSS) against impact (CVSS). Outside the shaded patch-first corner.
Where this sits among everything scored
Of 385,386 CVEs with a current EPSS score, this one falls in the 50–90% band (highlighted). Counts from FIRST.org, log-scaled.
Real-World Exposure
superset🐍apache-supersetReal-time download stats are indexed for npm and PyPI packages. This vulnerability affects PyPI packages — download data is not available via public APIs for these ecosystems.
Description
Apache Superset up to and including 1.0.1 allowed for the creation of an external URL that could be malicious. By not checking user input for open redirects the URL shortener functionality would allow for a malicious user to create a short URL for a dashboard that could convince the user to click the link.
Affected Packages
| Ecosystem | Package | Vulnerable range | Fix |
|---|---|---|---|
| 🐍PyPI | superset | all versions | No fix |
| 🐍PyPI | apache-superset | all versions | 1.1.0pip install --upgrade 'apache-superset==1.1.0' |
Affected Products
supersetapacheDetection & mitigation playbook
Open-source dependencyDetect
Scan your dependency tree (package-lock.json, pnpm-lock.yaml, requirements.txt, go.sum, etc.) for superset, including transitive dependencies — a direct dependency you never call can still pull in a vulnerable version.
Fix
No patched version of superset has shipped for CVE-2021-28125 yet. Where your build allows, override or pin the dependency away from the vulnerable range, and apply any maintainer-recommended mitigation.
Workarounds
Stop reflecting attacker-controlled destinations: resolve every redirect target against an allowlist of paths or hosts you own, prefer a server-side key over a full URL in the request, and reject absolute URLs entirely where the flow only ever needs a relative one.
Frequently Asked Questions
Is CVE-2021-28125 in your dependencies?
Find it across PyPI, including transitive dependencies.