Critical Vulnerability Information Vulnerability Title Unauthorized Problem Creation Severity Severity: High (7.6/10) Affected Scope Package: main-v2 (Flagforge) Affected versions: 2.1.0 Patched versions: 2.2.0 Description and Impact Impact: Non-administrator users can create arbitrary challenges, potentially introducing malicious, incorrect, or misleading content. This compromises the platform's integrity and reduces trust among legitimate users. Remediation Patches: Server-side admin authorization check implemented in the POST /api/problems endpoint. References OWASP Top10 2021 - A01:2021 - Broken Access Control CWE-862: Missing Authorization CVSS v3 Base Metrics Attack vector: Network Attack complexity: Low Privileges required: Low User interaction: None Scope: Unchanged Confidentiality: Low Integrity: High Availability: Low CVE ID CVE-2025-59826 Weaknesses Weaknesses: CWE-862 Discoverer Credits: aryan4859