Vulnerability record · CVE-2021-28125 · published 27 April 2021
CVE-2021-28125: Apache Superset URL shortener open redirect
Apache · Superset
Apache Superset up to and including 1.0.1 fails to validate user input in its URL shortener, allowing creation of short links that redirect to attacker-controlled external URLs. Because the short link appears to belong to the trusted Superset instance, it is a credible phishing lure against users of the platform.
Description
Apache Superset up to and including 1.0.1 allowed for the creation of an external URL that could be malicious. By not checking user input for open redirects the URL shortener functionality would allow for a malicious user to create a short URL for a dashboard that could convince the user to click the link.
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Automated analysis
medium priorityThe flaw is a medium-severity open redirect requiring user interaction with no direct compromise, though the high EPSS score and trusted-domain phishing value warrant prompt patching.
What it is
Apache Superset up to and including 1.0.1 fails to validate user input in its URL shortener, allowing creation of short links that redirect to attacker-controlled external URLs. Because the short link appears to belong to the trusted Superset instance, it is a credible phishing lure against users of the platform.
Impact
An attacker can craft a Superset-hosted short URL that redirects a victim to a malicious site, enabling credential phishing or malware delivery under the guise of a trusted dashboard link. The flaw itself yields no direct data access or code execution.
Attack surface
Reachable over the network through the URL shortener functionality; no authentication is required to create the malicious short URL, but the victim must click the link (UI:R). Scope is changed since the redirect lands on an external origin.
Exploitation
Not listed in CISA KEV and no public exploit references are tagged in the record; EPSS is high at roughly 0.64 (99th percentile), indicating elevated predicted exploitation likelihood despite the absence of confirmed in-the-wild activity.
What to do
- Upgrade Apache Superset past 1.0.1 to a release that validates redirect targets in the URL shortener.
- If immediate upgrade is not possible, restrict or disable the URL shortener feature until patched.
- Enforce an allowlist of permitted redirect destinations and reject external or absolute URLs.
- Place Superset behind a reverse proxy or web filter that blocks outbound redirects to untrusted domains.
- Train users not to trust short links, even those on the Superset domain, and verify destinations before clicking.
Detection
- Monitor Superset URL shortener creation and access logs for short links whose redirect target is an external domain.
- Alert on HTTP 3xx responses from the Superset host that point to non-allowlisted or newly registered domains.
- Review proxy and DNS logs for Superset-originated redirects to suspicious external hosts.
- Correlate user reports of unexpected redirects from Superset short links with shortener log entries.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2021-28125 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2021-28125), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.