External risk intelligence

FlagForge CTF API Vulnerability Exposes Badge Templates

CVE advisorySeverity: CRITICAL (CVSS 9.1)

CVE-2025-61777

Flag Forge is a Capture The Flag platform. Such platforms are designed as web applications intended to be accessed over the network by participants. Because the vulnerable endpoints are part of the web API that is typically exposed to users in a standard deployment, it is likely that this surface is reachable from the internet.

Information Disclosure

Flagforge

2.0 to before 2.3.2

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

This critical vulnerability in the Flag Forge CTF platform allowed unauthenticated access to sensitive badge template information and the ability to create new templates. This could have led to the exposure of internal metadata or the unauthorized modification of the badge system, potentially impacting data integrity and the platform's operational integrity. The issue has since been addressed through an update requiring authentication for all related endpoints.

  • Unauthenticated API access exposed sensitive data.
  • Admins must confirm if this CTF platform is used.
  • Confirm if this system is in your environment.

Attack Path

How an attacker could exploit the issue

An attacker could access unauthenticated API endpoints to retrieve sensitive badge template information or create new ones. This could expose details like who created the templates and when, and allow for the manipulation of the platform's badge system, potentially leading to data breaches or system abuse.

  • Network access, no authentication needed.
  • Accessing specific API endpoints.
  • Data exposure and system abuse.

Live Threat

Current exploitation, exposure, and threat context

This vulnerability could allow unauthorized users to access and modify badge templates within the Flag Forge platform, potentially exposing sensitive metadata associated with these templates and leading to the creation of arbitrary templates. This could occur when the platform is accessed over a network without proper authentication or authorization.

  • Badge templates and metadata at risk.
  • Unauthorized access to API endpoints.
  • Database pollution or badge system abuse.

Operational Fix

Recommended remediation, mitigation, and detection steps

The Flag Forge platform's administrative endpoints are affected, suggesting that the application owner or platform team is primarily responsible for remediation. The first practical step is to identify all instances of Flag Forge, determine their accessibility and criticality, and then confirm the accountable owner to plan a risk-based remediation.

  • App owners responsible for remediation.
  • Verify instance reachability and criticality.
  • Plan and execute secure update.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is Flag Forge and how is it used?

Flag Forge is a software platform designed for hosting Capture The Flag (CTF) cybersecurity competitions. It provides the infrastructure necessary to manage challenges, track scores, and handle administrative tasks like badge management. Organizations and security teams typically deploy this as a web application, allowing participants to interact with the platform over a network throughout the duration of a competition or training event.

What does CVE-2025-61777 mean for security?

This vulnerability is classified under weaknesses involving broken access control and missing authentication for critical functions. In plain terms, it means the application previously failed to verify the identity or permissions of users requesting specific administrative API paths. Because these checks were missing, unauthorized individuals could interact with sensitive badge template data as if they were platform administrators.

How can an attacker trigger this vulnerability?

An attacker triggers this by sending specific web requests to the affected API endpoints for badge templates without needing any login credentials. It is important to note that performing routine user activities, such as viewing standard challenge pages or navigating public parts of the CTF platform, does not involve these restricted administrative paths and would not inadvertently trigger this flaw.

Is my instance of Flag Forge at risk?

If you are running a version between 2.0.0 and 2.3.1, your system is vulnerable. According to Halo Surface Signal, because Flag Forge is a web-based platform intended for network participation, these API endpoints are often reachable from the internet. This increases the likelihood that an external actor could discover and interact with the vulnerable administrative functions if the instance is publicly exposed.

How do I secure my platform against this issue?

The only effective resolution is to update your software to version 2.3.2 or later. This update enforces mandatory authentication and authorization checks across all badge template endpoints, ensuring only verified administrators can access or modify them. You should prioritize identifying all running instances of Flag Forge in your environment and coordinating an update with the platform owners as soon as possible.

References