CVE-2025-59833
Last modified
CVE-2025-59833 is a high-severity vulnerability rated 7.5/10 on the CVSS scale. Flag Forge is a Capture The Flag (CTF) platform. In versions from 2.1.0 to before 2.3.0, the API endpoint GET /api/problems/:id returns challenge hints in plaintext within the question object, regardless of whether the user has unlocked them via point deduction. EPSS estimates a 0.32% chance of exploitation in the next 30 days.
Description
Flag Forge is a Capture The Flag (CTF) platform. In versions from 2.1.0 to before 2.3.0, the API endpoint GET /api/problems/:id returns challenge hints in plaintext within the question object, regardless of whether the user has unlocked them via point deduction. Users can view all hints for free, undermining the business logic of the platform and reducing the integrity of the challenge system. This issue has been patched in version 2.3.0.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Flagforge | Flagforge | >= 2.1.0, < 2.3 |
References
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2025-59833?
How severe is CVE-2025-59833?
How do I fix CVE-2025-59833?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2025
- CVE-2025-59828Claude Code is an agentic coding tool. Prior to Claude Code …9.8
- CVE-2025-59829Claude Code is an agentic coding tool. Versions below 1.0.12…6.5
- CVE-2025-5983The Meta Tag Manager WordPress plugin before 3.3 does not re…6.5
- CVE-2025-59830Rack is a modular Ruby web server interface. Prior to versio…7.5
- CVE-2025-59831git-commiters is a Node.js function module providing committ…8.8
- CVE-2025-59832Horilla is a free and open source Human Resource Management …9.9
- CVE-2025-59834ADB MCP Server is a MCP (Model Context Protocol) server for …9.8
- CVE-2025-59835LangBot is a global IM bot platform designed for LLMs. In ve…8.6
- CVE-2025-59836Omni manages Kubernetes on bare metal, virtual machines, or …7.5
- CVE-2025-59837Astro is a web framework that includes an image proxy. In ve…7.2
- CVE-2025-59838Monkeytype is a minimalistic and customizable typing test. I…5.4
- CVE-2025-59839The EmbedVideo Extension is a MediaWiki extension which adds…5.4
Are you affected by CVE-2025-59833?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
