---
id: CVE-2025-59932
title: Flag Forge is a Capture The Flag (CTF) platform
summary: >-
  Flag Forge is a Capture The Flag (CTF) platform. From versions 2.0.0 to before
  2.3.1, the /api/resources endpoint previously allowed POST and DELETE requests
  without proper authentication or authorization. This could have enabled
  unautho…
severity: high
cvss: 8.6
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:L'
cwe:
  - CWE-284
vendor: flagforge
product: flagforge
affected:
  - 'flagforge >= 2.0, < 2.3.1'
patched:
  - flagforge 2.3.1
published: '2025-09-27'
updated: '2026-10-09'
sourceUpdated: '2026-10-09T10:10:00.193'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-59932'
references:
  - url: >-
      https://github.com/FlagForgeCTF/flagForge/security/advisories/GHSA-v8rh-25rf-gfqw
    label: security-advisories@github.com
tags:
  - nvd
epss: 0.00367
epssPercentile: 0.2852
ingestedAt: '2026-10-09T12:53:27.949Z'
---

## Overview

Flag Forge is a Capture The Flag (CTF) platform. From versions 2.0.0 to before 2.3.1, the /api/resources endpoint previously allowed POST and DELETE requests without proper authentication or authorization. This could have enabled unauthorized users to create, modify, or delete resources on the platform. The issue has been fixed in FlagForge version 2.3.1.

## Affected

- `flagforge >= 2.0, < 2.3.1`

## Remediation

Upgrade past the affected range:

- `flagforge 2.3.1`
