cbcvebase.
CVE-2025-59826
published 2025-09-23

CVE-2025-59826: Flag Forge is a Capture The Flag (CTF) platform. In version 2.1.0, non-admin users can create arbitrary challenges, potentially introducing malicious…

PriorityP346high7.6CVSS 3.1
AVNACLPRLUINSUCLIHAL
EPSS
0.21%
11.8th percentile
Flag Forge is a Capture The Flag (CTF) platform. In version 2.1.0, non-admin users can create arbitrary challenges, potentially introducing malicious, incorrect, or misleading content. This issue has been patched in version 2.2.0.

Affected

2 ranges
VendorProductVersion rangeFixed in
flagforgeflagforge
flagforgectfflagforge
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.