Flag Forge is a Capture The Flag (CTF) platform. From versions 2.0.0 to before 2.3.2, the public endpoint /api/user/[username] returns user email addresses in its JSON response. The fix, intended for release in 2.3.1 but only available starting in version 2.3.2, removes email addresses from public API responses while keeping the endpoint publicly accessible. Users should upgrade to version 2.3.2 or later to eliminate exposure. There are no workarounds for this vulnerability.
Metrics
Affected Vendors & Products
References
History
Wed, 28 Jan 2026 23:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Flag Forge is a Capture The Flag (CTF) platform. From versions 2.0.0 to before 2.3.1, the public endpoint /api/user/[username] returns user email addresses in its JSON response. The problem has been patched in FlagForge version 2.3.1. The fix removes email addresses from public API responses while keeping the endpoint publicly accessible. Users should upgrade to version 2.3.1 or later to eliminate exposure. There are no workarounds for this vulnerability. | Flag Forge is a Capture The Flag (CTF) platform. From versions 2.0.0 to before 2.3.2, the public endpoint /api/user/[username] returns user email addresses in its JSON response. The fix, intended for release in 2.3.1 but only available starting in version 2.3.2, removes email addresses from public API responses while keeping the endpoint publicly accessible. Users should upgrade to version 2.3.2 or later to eliminate exposure. There are no workarounds for this vulnerability. |
| References |
|
Wed, 08 Oct 2025 16:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Flagforge
Flagforge flagforge |
|
| CPEs | cpe:2.3:a:flagforge:flagforge:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Flagforge
Flagforge flagforge |
|
| Metrics |
cvssV3_1
|
Mon, 29 Sep 2025 09:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Flagforgectf
Flagforgectf flagforge |
|
| Vendors & Products |
Flagforgectf
Flagforgectf flagforge |
Fri, 26 Sep 2025 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 26 Sep 2025 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Flag Forge is a Capture The Flag (CTF) platform. From versions 2.0.0 to before 2.3.1, the public endpoint /api/user/[username] returns user email addresses in its JSON response. The problem has been patched in FlagForge version 2.3.1. The fix removes email addresses from public API responses while keeping the endpoint publicly accessible. Users should upgrade to version 2.3.1 or later to eliminate exposure. There are no workarounds for this vulnerability. | |
| Title | FlagForgeCTF Exposes User Emails via Public /api/user/[username] API | |
| Weaknesses | CWE-359 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: GitHub_M
Published: 2025-09-26T16:03:34.038Z
Updated: 2026-01-28T23:11:20.765Z
Reserved: 2025-09-22T14:34:03.472Z
Link: CVE-2025-59843
Updated: 2025-09-26T17:35:32.509Z
Status : Modified
Published: 2025-09-26T16:15:49.090
Modified: 2026-01-29T00:16:07.250
Link: CVE-2025-59843
No data.