CVE-2024-34699: Gztimewalker Gzctf

Medium severity, CVSS 6.5. EPSS: 0.6% chance of exploitation in the next 30 days.

GZ::CTF is a capture the flag platform. Prior to 0.20.1, unprivileged user can perform cross-site scripting attacks on other users by constructing malicious team names. This problem has been fixed in `v0.20.1`.

Affected products

Published 2024-05-14. Last modified 2026-06-17.