CVE-2026-30345: High severity CTFd CTFd vulnerability
Published Mar 18, 2026
·Updated
A zip slip vulnerability in the Admin import functionality of CTFd v3.8.1-18-gdb5a18c4 allows attackers to write arbitrary files outside the intended directories via supplying a crafted import.
Affected Software
1 affected component
CTFd CTFd
Event History
Mar 18, 2026
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·05:16 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2026-30345?
The severity of CVE-2026-30345 is considered high due to the potential for arbitrary file writing outside intended directories.
2
How do I fix CVE-2026-30345?
To fix CVE-2026-30345, update CTFd to the latest version where the vulnerability has been patched.
3
What impact does CVE-2026-30345 have on my system?
CVE-2026-30345 can allow attackers to manipulate the file system, potentially leading to unauthorized access or data breaches.
4
In which version of CTFd does CVE-2026-30345 exist?
CVE-2026-30345 affects CTFd version v3.8.1-18-gdb5a18c4.
5
Who is affected by CVE-2026-30345?
Any user or administrator employing the vulnerable version of CTFd is at risk due to CVE-2026-30345.