CVE-2026-78145
LOW
2,1
Source: [email protected]
Attack Vector: network
Attack Complexity: low
Privileges Required: none
User Interaction: passive
Confidentiality: N/A
Integrity: N/A
Availability: N/A
MEDIUM
4,3
Source: [email protected]
Attack Vector: network
Attack Complexity: low
Privileges Required: none
User Interaction: required
Scope: unchanged
Confidentiality: none
Integrity: low
Availability: none
MEDIUM
5,0
Source: [email protected]
Access Vector: network
Access Complexity: low
Authentication: none
Confidentiality: none
Integrity: partial
Availability: none
Description
AI Translation Available
A vulnerability has been found in CTFd up to 3.8.4. The affected element is the function _is_safe_url of the file CTFd/utils/validators/__init__.py. Such manipulation of the argument Next leads to open redirect. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The name of the patch is 5d8515842fd1ab2c3a9f2dde9ffca907aa334ea9. Upgrading the affected component is recommended.
601
URL Redirection to Untrusted Site ('Open Redirect')
DraftCommon Consequences
Security Scopes Affected:
Access Control
Confidentiality
Other
Potential Impacts:
Bypass Protection Mechanism
Gain Privileges Or Assume Identity
Other
Applicable Platforms
Technologies:
Web Based, Web Server
https://github.com/CTFd/CTFd/
https://github.com/CTFd/CTFd/commit/5d8515842fd1ab2c3a9f2dde9ffca907aa334ea9
https://github.com/CTFd/CTFd/pull/3026
https://github.com/CTFd/CTFd/releases/tag/3.8.4
https://mblunt.dev/writeups/ctfd-open-redirect/
https://vuldb.com/cve/CVE-2026-78145
https://vuldb.com/submit/882469
https://vuldb.com/vuln/394533
https://vuldb.com/vuln/394533/cti