Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

cvat-ai — Vulnerabilities & Security Advisories 22

Browse all 22 CVE security advisories affecting cvat-ai. AI-powered Chinese analysis, POCs, and references for each vulnerability.

CVAT-AI is an open-source computer annotation tool primarily used for labeling visual data in machine learning pipelines. Historically, it has been susceptible to multiple remote code execution vulnerabilities, cross-site scripting attacks, and privilege escalation flaws, with 15 CVEs documented to date. The platform's web interface and API have been frequent attack vectors due to insufficient input validation and authentication bypasses. While no major public security incidents have been reported, the consistent discovery of critical vulnerabilities suggests ongoing security challenges for organizations deploying this tool in production environments.

Found 22 results / 22 Clear Filters
Top products by cvat-ai: cvat
CVE ID Title CVSS Severity Published
CVE-2026-73220 CVAT: Stored XSS via annotation guides in audio tasks — cvat CWE-80 8.5 High 2026-08-20
CVE-2026-73221 CVAT: Flawed authorization logic in endpoints related to lambda requests — cvat CWE-863 5.3 Medium 2026-08-11
CVE-2026-73219 CVAT: Denial of service with regards to automatic annotation — cvat CWE-1288 5.3 Medium 2026-08-11
CVE-2026-65986 CVAT has stored XSS via annotation guide assets — cvat CWE-79 8.5 High 2026-08-04
CVE-2026-47682 CVAT: Missing path-containment validation in multiple entry points allows arbitrary path writes — cvat CWE-22 7.1 High 2026-08-04
CVE-2026-58373 CVAT < 2.69.0 - Missing Authorization on Quality Reports parent_id Filter Leaks Cross-Organization Report Existence — cvat CWE-862 4.3 Medium 2026-06-30
CVE-2026-44369 CVAT: Stored XSS via annotation guides — cvat CWE-80 - - 2026-05-13
CVE-2026-23526 CVAT vulnerable to privilege escalation of users with staff status — cvat CWE-267 6.5AI Medium AI 2026-01-21
CVE-2026-23516 CVAT vulnerable to XSS via skeleton SVG images — cvat CWE-83 6.5AI Medium AI 2026-01-21
CVE-2025-68430 CVAT vulnerable to directory traversal via mounted share listing — cvat CWE-24 4.3AI Medium AI 2025-12-19
CVE-2025-64485 CVAT: Mounted share file overwrite via crafted request — cvat CWE-22 7.1 - 2025-11-07
CVE-2025-54573 CVAT vulnerable to email verification bypass by use of basic authentication — cvat CWE-287 4.3 Medium 2025-07-30
CVE-2025-49135 CVAT missing validation for in-progress backup upload names — cvat CWE-639 6.5AI Medium AI 2025-06-25
CVE-2025-48381 CVAT has information disclosure via browsable API — cvat CWE-201 4.3AI Medium AI 2025-05-30
CVE-2025-23045 CVAT allows remote code execution via tracker Nuclio functions — cvat CWE-502 8.8 - 2025-01-28
CVE-2024-47172 Computer Vision Annotation Tool (CVAT) access control is broken in several PATCH endpoints — cvat CWE-863 5.4 Medium 2024-09-30
CVE-2024-47064 Computer Vision Annotation Tool (CVAT) contains a reflected XSS via request endpoints — cvat CWE-79 6.5 - 2024-09-30
CVE-2024-47063 Computer Vision Annotation Tool (CVAT) contains a stored XSS via the quality report data endpoint — cvat CWE-79 6.5 - 2024-09-30
CVE-2024-45393 Computer Vision Annotation Tool (CVAT) is missing authorization for endpoints related to webhook deliveries — cvat CWE-862 6.4 Medium 2024-09-10
CVE-2024-37306 CVAT's export and backup-related API endpoints are susceptible to CSRF — cvat CWE-352 7.1 High 2024-06-13
CVE-2024-37164 CVAT SSRF via custom cloud storage endpoints — cvat CWE-918 7.1 High 2024-06-13
CVE-2022-31188 Server-Side Request Forgery Vulnerability in Computer Vision Annotation Tool (CVAT) — cvat CWE-918 8.6 High 2022-08-01

This page lists every published CVE security advisory associated with cvat-ai. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.