{"id":"CVE-2021-32670","aliases":["GHSA-gff3-739c-gxfq","GHSA-xw7c-jx9m-xh5g","PYSEC-2021-89"],"url":"https://o3.security/vulnerability/CVE-2021-32670","summary":"Duplicate Advisory: Reflected cross-site scripting issue in Datasette","details":"## Duplicate Advisory\nThis advisory has been withdrawn because it is a duplicate of GHSA-xw7c-jx9m-xh5g. This link is maintained to preserve external references.\n\n## Original Description\nDatasette is an open source multi-tool for exploring and publishing data. The `?_trace=1` debugging feature in Datasette does not correctly escape generated HTML, resulting in a [reflected cross-site scripting](https://owasp.org/www-community/attacks/xss/#reflected-xss-attacks) vulnerability. This vulnerability is particularly relevant if your Datasette installation includes authenticated features using plugins such as [datasette-auth-passwords](https://datasette.io/plugins/datasette-auth-passwords) as an attacker could use the vulnerability to access protected data. Datasette 0.57 and 0.56.1 both include patches for this issue. If you run Datasette behind a proxy you can workaround this issue by rejecting any incoming requests with `?_trace=` or `&_trace=` in their query string parameters.","published":"2021-06-07T22:15:07.650Z","modified":"2026-07-09T10:12:08.776763Z","cvss":{"score":6.1,"severity":"MEDIUM","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"},"epss":null,"cisaKev":null,"exploitsKnown":null,"affectedPackages":[{"ecosystem":"PyPI","name":"datasette","fixedVersion":"0.56.1"}],"fix":null,"references":[{"type":"ADVISORY","url":"https://datasette.io/plugins/datasette-auth-passwords"},{"type":"ADVISORY","url":"https://github.com/simonw/datasette/security/advisories/GHSA-xw7c-jx9m-xh5g"},{"type":"ADVISORY","url":"https://owasp.org/www-community/attacks/xss/#reflected-xss-attacks"},{"type":"ADVISORY","url":"https://pypi.org/project/datasette/"},{"type":"FIX","url":"https://github.com/simonw/datasette/issues/1360"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2021-32670"},{"type":"WEB","url":"https://pypi.org/project/datasette"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-07-09T10:12:08.776763Z"}}