LeakyCreds
NewInstant webhook alerts now available — notified within seconds of any credential detection.Learn more →
Home / Vulnerability Intelligence / CVE-2026-30345

CVE-2026-30345 - Vulnerability Analysis

HighCVSS: 7.5

Last Updated: March 19, 2026

CTFd - Path Traversal

Published: March 18, 2026Updated: March 19, 2026PoC AvailableRemote Exploitable

Overview

CTFd v3.8.1-18-gdb5a18c4 contains a path traversal caused by crafted import in Admin import functionality, letting attackers write arbitrary files outside intended directories, exploit requires no special privileges.

Severity & Score

Severity: High
CVSS Score: 7.5

Impact

Attackers can write arbitrary files outside intended directories, potentially leading to system compromise or data tampering.

Mitigation

Update to the latest version of CTFd.

Details

CVE ID
CVE-2026-30345
Severity
High
CVSS Score
7.5
Type
path_traversal
Status
unconfirmed

CWE

  • CWE-23

CVSS Metrics

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N