Flag Forge Capture The Flag Platform Privilege Escalation Vulnerability

Vulnerability

A vulnerability in Flag Forge CTF platform version 2.1.0 allows any authenticated user to assign high-privilege badges, such as Staff, to themselves via the /api/admin/assign-badge endpoint. This issue arises from inadequate access control, potentially leading to unauthorized privilege escalation and impersonation of administrative roles.

Impact

Exploitation of this vulnerability could result in unauthorized users gaining administrative privileges, allowing them to impersonate staff members and possibly misuse those privileges within the application.

Remediation

Users can upgrade to Flag Forge version 2.2.0, which addresses this vulnerability by implementing proper authentication and authorization checks on badge assignment endpoints. Instructions for updating can be found in the Flag Forge repository.

Added: Sep 24, 2025, 10:00 PM
Updated: Sep 24, 2025, 10:00 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
5.0
exploitability
6.6
remediation
7.7
relevance
0.6
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.