CVE-2025-29419: CTFd CTFd vulnerability
Published Aug 26, 2026
·Updated
CTFd v3.7.6 was discovered to be vulnerable to a man-in-the-middle attack.
Affected Software
1 affected component
CTFd CTFd=3.7.6
Event History
Aug 26, 2026
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·06:16 PM
Description
Frequently Asked Questions
1
What conditions are required for exploitation?
An attacker must be able to position themselves as a man-in-the-middle between a user and the CTFd v3.7.6 deployment, allowing them to intercept or alter traffic.
2
Which deployments should be considered potentially exposed?
Deployments running CTFd v3.7.6 should be considered potentially affected where an attacker can perform a man-in-the-middle attack. The available information does not state whether particular configurations or transport protections prevent exposure.