Back to Database
Status published
High
CVE-2025-59826
FlagForgeCTF Vulnerable to Unauthorized Problem Creation
Vulnerability Description
Flag Forge is a Capture The Flag (CTF) platform. In version 2.1.0, non-admin users can create arbitrary challenges, potentially introducing malicious, incorrect, or misleading content. This issue has been patched in version 2.2.0.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-59826
Credits & Attribution
No credits recorded in the NVD database.
More from FlagForgeCTF
View All →CVE-2025-61777
FlagForge Allows Unauthenticated Badge Template API Access
Critical
9.4
CVE-2025-59932
FlagForgeCTF Unauthenticated Resource Modification/Deletion
High
8.6
CVE-2025-59843
FlagForgeCTF Exposes User Emails via Public /api/user/[username] API
Medium
6.9
CVE-2025-59841
FlagForgeCTF's Improper Session Handling Allows Access After Logout
Critical
9.8
CVE-2025-59833
FlagForgeCTF Hint Exposure via API
High
7.5
Affected Vendor
FlagForgeCTF
View all reports →Affected Software
flagForge
Vulnerable Versions:
= 2.1.0
Timeline
Official Publish:
September 23rd, 2025
Last Modified:
September 24th, 2025
Added to House:
July 22nd, 2026
CVSS Vectors
V3:
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:L