CVE-2026-78145 | CTFd up to 3.8.4 __init__.py _is_safe_url Next redirect
A vulnerability described as problematic has been identified in CTFd up to 3.8.4. The affected element is the function _is_safe_url of the file CTFd/utils/validators/__init__.py. Such manipulation of the argument Next leads to open redirect.
This vulnerability is uniquely identified as CVE-2026-78145. The attack can be launched remotely. Moreover, an exploit is present.
Upgrading the affected component is recommended.VulDB Recent EntriesRead More