CVE-2026-78145

Source
https://cve.org/CVERecord?id=CVE-2026-78145
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-78145.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-78145
Published
2026-08-23T22:45:11Z
Modified
2026-08-27T11:31:02Z
Severity
  • 2.1 (Low) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:P CVSS Calculator
Summary
CTFd __init__.py _is_safe_url redirect
Details

A vulnerability has been found in CTFd up to 3.8.4. The affected element is the function _is_safe_url of the file CTFd/utils/validators/init.py. Such manipulation of the argument Next leads to open redirect. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The name of the patch is 5d8515842fd1ab2c3a9f2dde9ffca907aa334ea9. Upgrading the affected component is recommended.

Database specific
{
    "cna_assigner": "VulDB",
    "cwe_ids": [
        "CWE-601"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/78xxx/CVE-2026-78145.json"
}
References

Affected packages

Git / github.com/ctfd/ctfd

Affected ranges

Type
GIT
Repo
https://github.com/ctfd/ctfd
Events
Database specific
Show details
{
    "extracted_events": [
        {
            "introduced": "3.8.0"
        },
        {
            "last_affected": "3.8.0"
        },
        {
            "introduced": "3.8.1"
        },
        {
            "last_affected": "3.8.1"
        },
        {
            "introduced": "3.8.2"
        },
        {
            "last_affected": "3.8.2"
        },
        {
            "introduced": "3.8.3"
        },
        {
            "last_affected": "3.8.3"
        },
        {
            "introduced": "3.8.4"
        },
        {
            "last_affected": "3.8.4"
        }
    ],
    "source": [
        "AFFECTED_FIELD",
        "REFERENCES"
    ]
}

Affected versions

3.*
3.8.0
3.8.1
3.8.2
3.8.3
3.8.4

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-78145.json"