Impact
CTFd version 3.7.6 is susceptible to a man-in-the-middle attack, allowing an adversary to intercept, modify or inject traffic between the client and server. This flaw compromises the confidentiality and integrity of all transmitted data, potentially exposing credentials, challenge submissions, or any sensitive information exchanged during competition use. The vulnerability arises from insufficient or improper encryption handling, enabling an attacker to position themselves between legitimate participants and the platform.
Affected Systems
The only explicitly affected product is the open‑source CTFd platform running version 3.7.6. Any deployment using this exact version, regardless of hosting environment, is vulnerable if traffic is not protected by robust TLS or other secure transport mechanisms.
Risk and Exploitability
The exploit vector requires network connectivity to the vulnerable instance and the ability to redirect or inject traffic. Because the report lists no CVSS or EPSS data, the exact quantitative risk is unclear; however, a MITM flaw of this nature is typically high impact and can be leveraged with minimal skill if clients do not enforce HTTPS or verify certificates. No known exploits are listed in the CISA KEV catalog.
OpenCVE Enrichment