CVE-2026-78145General

LOWCVSS 2.1 · LOW

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

A vulnerability has been found in CTFd up to 3.8.4. The affected element is the function _is_safe_url of the file CTFd/utils/validators/__init__.py. Such manipulation of the argument Next leads to open redirect. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The name of the patch is 5d8515842fd1ab2c3a9f2dde9ffca907aa334ea9. Upgrading the affected component is recommended.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-601

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Patch or workaround signal is available
  • 4 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 3 signals
  • General: 2 classified signals
  • Disclosure: 1 classified signal
  • Peaked 1d ago at 3 mentions (2026-08-23); latest day: 1
  • 4 total mentions across 2 days

Deep dive

Activity timeline4 mentions / 2d
01223Mentions · 2026-08-23: 3Mentions · 2026-08-24: 1Patch / Workaround · 2026-08-24: 1Technical Details · 2026-08-23: 2Technical Details · 2026-08-24: 108-2308-24
Signal classification3 categories
General
250.0%
Disclosure
125.0%
Patch
125.0%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-08-233
Disclosure1General2
2026-08-241
Patch1
Full discourse4 posts
  • CVE@CVEnew
    General

    CVE-2026-78145 A vulnerability has been found in CTFd up to 3.8.4. The affected element is the function _is_safe_url of the file CTFd/utils/validators/__init__.py. Such manipulation… https://www.cve.org/CVERecord?id=CVE-2026-78145

    Post summary

    The message reports a CVE affecting CTFd versions up to 3.8.4, specifically targeting the _is_safe_url function, but provides no additional exploitation or mitigation details.

    000201.3K
    58.1K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-78145 Open Redirect Vulnerability in CTFd Up To 3.8.4 Via _is_safe_url Function https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-78145

    Post summary

    The text announces an open redirect flaw in CTFd versions up to 3.8.4 that leverages the _is_safe_url function, providing a brief technical detail but lacking PoC, exploit, or patch information.

    00010126
    4.1K followersView on X
  • RENU-CERT@renu_cert
    Patch

    Security Alert: CVE-2026-78145 affects CTFd versions up to 3.8.4 and could enable phishing through an open redirect vulnerability. Administrators are advised to upgrade to CTFd 3.8.5 or later. Learn more: https://www.rapid7.com/db/vulnerabilities/cve-2026-78145/ #CyberSecurity

    Post summary

    The alert highlights CVE-2026-78145, an open‑redirect flaw in CTFd up to 3.8.4, and advises upgrading to mitigate the risk.

    0000078
    632 followersView on X
  • Infoflowcloud@infoflowcloud
    General

    🚨*CVE* CVE-2026-78145 A vulnerability has been found in CTFd up to 3.8.4. The affected element is the function _is_safe_url of the file CTFd/utils/validators/__init__.py. Such manipulation… https://www.cve.org/CVERecord?id=CVE-2026-78145 ----- Traducción: CVE-2026-78145 Se … http://infoflow.cloud`

    Post summary

    The post announces CVE‑2026‑78145 in CTFd up to 3.8.4, notes the vulnerable _is_safe_url function and file path, and links to the official CVE record, but offers no PoC, exploit, patch, or activity details.

    00000121
    102 followersView on X

Explore more