Flag Forge is a Capture The Flag (CTF) platform. From versions 2.0.0 to before 2.3.1, the public endpoint /api/user/[username] returns user email addresses in its JSON response. The problem has been patched in FlagForge version 2.3.1. The fix removes email addresses from public API responses while keeping the endpoint publicly accessible. Users should upgrade to version 2.3.1 or later to eliminate exposure. There are no workarounds for this vulnerability.
History

Wed, 08 Oct 2025 16:45:00 +0000

Type Values Removed Values Added
First Time appeared Flagforge
Flagforge flagforge
CPEs cpe:2.3:a:flagforge:flagforge:*:*:*:*:*:*:*:*
Vendors & Products Flagforge
Flagforge flagforge
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N'}


Mon, 29 Sep 2025 09:45:00 +0000

Type Values Removed Values Added
First Time appeared Flagforgectf
Flagforgectf flagforge
Vendors & Products Flagforgectf
Flagforgectf flagforge

Fri, 26 Sep 2025 18:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 26 Sep 2025 16:15:00 +0000

Type Values Removed Values Added
Description Flag Forge is a Capture The Flag (CTF) platform. From versions 2.0.0 to before 2.3.1, the public endpoint /api/user/[username] returns user email addresses in its JSON response. The problem has been patched in FlagForge version 2.3.1. The fix removes email addresses from public API responses while keeping the endpoint publicly accessible. Users should upgrade to version 2.3.1 or later to eliminate exposure. There are no workarounds for this vulnerability.
Title FlagForgeCTF Exposes User Emails via Public /api/user/[username] API
Weaknesses CWE-359
References
Metrics cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:L/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published: 2025-09-26T16:03:34.038Z

Updated: 2025-09-26T17:51:22.644Z

Reserved: 2025-09-22T14:34:03.472Z

Link: CVE-2025-59843

cve-icon Vulnrichment

Updated: 2025-09-26T17:35:32.509Z

cve-icon NVD

Status : Analyzed

Published: 2025-09-26T16:15:49.090

Modified: 2025-10-08T16:30:36.180

Link: CVE-2025-59843

cve-icon Redhat

No data.