📦 Computer Vision Annotation Tool

by Cvat

🔍 What is Computer Vision Annotation Tool?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2025-23045

CRITICAL CVSS 9.8 Jan 28, 2025

This vulnerability allows authenticated attackers to execute arbitrary code within CVAT's Nuclio function containers by exploiting unsafe serialization in tracker functions. It affects CVAT deployment...

CVE-2021-45046

CRITICAL CVSS 9.0 Dec 14, 2021

CVE-2021-45046 is an incomplete fix for the Log4Shell vulnerability (CVE-2021-44228) in Apache Log4j 2.15.0 that allows attackers to execute arbitrary code via JNDI lookups in certain non-default logg...

CVE-2026-23526

HIGH CVSS 8.8 Jan 21, 2026

CVAT users with staff status can escalate their own privileges to superuser/admin level, gaining full access to all data in the CVAT instance. This affects all CVAT deployments running versions 1.0.0 ...

CVE-2024-37306

HIGH CVSS 7.1 Jun 13, 2024

This is a Cross-Site Request Forgery (CSRF) vulnerability in CVAT that allows attackers to trick authenticated users into performing unauthorized dataset exports or backups to cloud storage. Attackers...

CVE-2026-23516

MEDIUM CVSS 5.4 Jan 21, 2026

This cross-site scripting (XSS) vulnerability in CVAT allows attackers to execute arbitrary JavaScript in victims' browser sessions by creating malicious labels or SVG images. Users of CVAT versions 2...

CVE-2025-54573

MEDIUM CVSS 4.3 Jul 30, 2025

CVAT versions 1.1.0 through 2.41.0 do not enforce email verification when using Basic HTTP Authentication, allowing attackers to create accounts with fake email addresses and use the system as verifie...

CVE-2025-49135

MEDIUM CVSS 6.5 Jun 25, 2025

This vulnerability in CVAT allows authenticated users with 'user' role to access other users' uploaded files during project/task backup imports by exploiting filename validation flaws. It affects all ...

CVE-2025-48381

MEDIUM CVSS 4.3 May 30, 2025

This vulnerability allows authenticated CVAT users to enumerate all task, project, label, job, and quality report IDs and names on the instance. It can also cause resource exhaustion if many resources...

CVE-2024-45393

MEDIUM CVSS 6.4 Sep 10, 2024

This vulnerability in CVAT allows authenticated attackers to view webhook delivery information for any webhook on the instance, including those belonging to other users. Attackers can also redeliver p...