PT-2026-79787 · Ctfd · Ctfd

·

CVE-2026-78145

·

Published

2026-08-23

·

Updated

2026-08-24

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions CTFd versions prior to 3.8.5
Description An open redirect issue exists where remote attackers can manipulate the Next argument. This occurs within the is safe url() function located in the CTFd/utils/validators/ init .py file.
Recommendations Update to a version newer than 3.8.4. As a temporary mitigation, restrict or validate the input passed to the Next argument to prevent redirection to untrusted domains.

Exploit

Fix

Open Redirect

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-78145

Affected Products

Ctfd