CVE-2026-78145
Last modified
CVE-2026-78145 is a medium-severity vulnerability rated 4.3/10 on the CVSS scale. A vulnerability has been found in CTFd up to 3.8.4. The affected element is the function _is_safe_url of the file CTFd/utils/validators/__init__.py.
Description
A vulnerability has been found in CTFd up to 3.8.4. The affected element is the function _is_safe_url of the file CTFd/utils/validators/__init__.py. Such manipulation of the argument Next leads to open redirect. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The name of the patch is 5d8515842fd1ab2c3a9f2dde9ffca907aa334ea9. Upgrading the affected component is recommended.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N/E:P/RL:O/RC:C
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| — | CTFd | 3.8.0; 3.8.1; 3.8.2; 3.8.3; 3.8.4 |
References
Timeline
- Published
- Last Modified
- Status
- Received
Frequently Asked Questions
What is CVE-2026-78145?
How severe is CVE-2026-78145?
How do I fix CVE-2026-78145?
How Strix Helps
- One Click Account Takeover in GranolaHow a notification link broke out of Electron and led to a one-click account takeover.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-7814Stored cross-site scripting (XSS) vulnerability in pgAdmin 4…4.8
- CVE-2026-78140A flaw has been found in Dromara UJCMS up to 10.1.3. The imp…4.7
- CVE-2026-78141A vulnerability has been found in Tenda CH22 1.0.0.1. This a…7.4
- CVE-2026-78142A vulnerability was found in code-projects Barangay Resident…6.3
- CVE-2026-78143A vulnerability was determined in code-projects Barangay Res…7.3
- CVE-2026-78144A vulnerability was identified in code-projects Barangay Res…6.3
- CVE-2026-78147A vulnerability was found in ggml-org llama.cpp bec4772f6. T…7.3
- CVE-2026-78148A vulnerability was determined in ggml-org llama.cpp bec4772…5.3
- CVE-2026-7815SQL injection vulnerability in pgAdmin 4 Maintenance Tool. …8.8
- CVE-2026-78154A vulnerability was identified in the-momentum open-wearable…7.3
- CVE-2026-78155privilege escalation in StackGres operator allows a low-priv…9.9
- CVE-2026-78156A security vulnerability has been detected in Open5GS 2.8.0.…7.4
Are you affected by CVE-2026-78145?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
