Junglewise Threat Intelligence

CVE-2025-29419: CTFd man-in-the-middle attack vulnerability

CVE-2025-29419 · Severity: high · CVSS 7.1 · Published 2026-08-26

Executive brief

CTFd is a platform used to host Capture The Flag (CTF) cybersecurity competitions. A man-in-the-middle vulnerability in version 3.7.6 allows attackers on the network path to intercept and potentially modify communications between users and the platform, compromising the integrity of competition data and user sessions.

Technical details

CTFd v3.7.6 is vulnerable to a man-in-the-middle (MITM) attack, allowing an attacker positioned on the network to intercept communications between clients and the server. The vulnerability likely stems from insufficient encryption, missing or improper HTTPS/TLS enforcement, or improper certificate validation. An attacker on the network path (adjacent network position or compromised intermediate network device) can intercept, read, and modify traffic without requiring authentication. This could allow attackers to steal session tokens, modify challenge submissions, or redirect users to malicious servers. Patched versions should be available from CTFd's repository.

Affected products

  • CTFd CTFd 3.7.6

Timeline

  • 2026-08-26: disclosed

References

Related threats