Cvat
Cvat Computer Vision Annotation Tool: vulnerabilities and CVEs
Cvat Computer Vision Annotation Tool has 16 published vulnerabilities, 4 of them in the last 12 months. 2 are rated critical and 1 are listed by CISA as actively exploited.
CVEs16
Last 12 months4
Critical2
Actively exploited1
All vulnerabilities in the catalogue →⭐ Follow this technology
🔴 Actively exploited (CISA KEV)
| CVE | Severity | EPSS | Active exploitation | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-45046 | Critical (9) | 100% | ⚠ Active exploitation | Dec 14, 2021 | It was found that the fix to address CVE-2021-44228 in Apache Log4j 2.15.0 was incomplete in certain non-default configurations. This could allows attackers with control over Thread Context Map (MDC) input data when the… |
Latest vulnerabilities
| CVE | Severity | EPSS | Active exploitation | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-58373 | Medium (5.3) | 0.34% | — | Jun 30, 2026 | CVAT before 2.69.0 contains an improper authorization vulnerability in QualityReportViewSet.get_queryset that allows authenticated attackers to enumerate quality report identifiers belonging to other organizations by… |
| CVE-2026-23526 | High (8.5) | 0.29% | — | Jan 21, 2026 | CVAT is an open source interactive video and image annotation tool for computer vision. In versions 1.0.0 through 2.54.0, users that have the staff status may freely change their permissions, including giving themselves… |
| CVE-2026-23516 | High (8.6) | 0.17% | — | Jan 21, 2026 | CVAT is an open source interactive video and image annotation tool for computer vision. In versions 2.2.0 through 2.54.0, an attacker is able to execute arbitrary JavaScript in a victim user's CVAT UI session, provided… |
| CVE-2025-68430 | Medium (5.3) | 0.29% | — | Dec 19, 2025 | CVAT is an open source interactive video and image annotation tool for computer vision. In versions 2.8.1 through 2.52.0, an attacker with an account on a CVAT instance is able to retrieve the contents of any file… |
| CVE-2025-54573 | Medium (6.5) | 0.27% | — | Jul 30, 2025 | CVAT is an open source interactive video and image annotation tool for computer vision. In versions 1.1.0 through 2.41.0, email verification was not enforced when using Basic HTTP Authentication. As a result, users… |
| CVE-2025-49135 | Medium (5.3) | 0.30% | — | Jun 25, 2025 | CVAT is an open source interactive video and image annotation tool for computer vision. Versions 2.2.0 through 2.39.0 have no validation during the import process of a project or task backup to check that the filename… |
| CVE-2025-48381 | Medium (5.3) | 0.28% | — | May 30, 2025 | Computer Vision Annotation Tool (CVAT) is an interactive video and image annotation tool for computer vision. In versions starting from 2.4.0 to before 2.38.0, an authenticated CVAT user may be able to retrieve the IDs… |
| CVE-2025-23045 | High (8.7) | 0.50% | — | Jan 28, 2025 | Computer Vision Annotation Tool (CVAT) is an interactive video and image annotation tool for computer vision. An attacker with an account on an affected CVAT instance is able to run arbitrary code in the context of the… |
| CVE-2024-47172 | Medium (5.4) | 0.26% | — | Sep 30, 2024 | Computer Vision Annotation Tool (CVAT) is an interactive video and image annotation tool for computer vision. An attacker with a CVAT account may retrieve certain information about any project, task, job or membership… |
| CVE-2024-47064 | Medium (6.3) | 0.31% | — | Sep 30, 2024 | Computer Vision Annotation Tool (CVAT) is an interactive video and image annotation tool for computer vision. If an attacker can trick a logged-in CVAT user into visiting a maliciously-constructed URL, they can initiate… |
| CVE-2024-47063 | Medium (6.2) | 0.30% | — | Sep 30, 2024 | Computer Vision Annotation Tool (CVAT) is an interactive video and image annotation tool for computer vision. If a malicious CVAT user with permissions to either create a task, or edit an existing task can trick another… |
| CVE-2024-45393 | Medium (6.4) | 0.24% | — | Sep 10, 2024 | Computer Vision Annotation Tool (CVAT) is an interactive video and image annotation tool for computer vision. An attacker with a CVAT account can access webhook delivery information for any webhook registered on the… |
| CVE-2024-37306 | High (7.1) | 0.21% | — | Jun 13, 2024 | Computer Vision Annotation Tool (CVAT) is an interactive video and image annotation tool for computer vision. Starting in version 2.2.0 and prior to version 2.14.3, if an attacker can trick a logged-in CVAT user into… |
| CVE-2024-37164 | High (8.5) | 0.35% | — | Jun 13, 2024 | Computer Vision Annotation Tool (CVAT) is an interactive video and image annotation tool for computer vision. CVAT allows users to supply custom endpoint URLs for cloud storages based on Amazon S3 and Azure Blob… |
| CVE-2022-31188 | Critical (9.8) | 49% | — | Aug 1, 2022 | CVAT is an opensource interactive video and image annotation tool for computer vision. Versions prior to 2.0.0 were found to be subject to a Server-side request forgery (SSRF) vulnerability. Validation has been added to… |
| CVE-2021-45046 | Critical (9) | 100% | ⚠ Active exploitation | Dec 14, 2021 | It was found that the fix to address CVE-2021-44228 in Apache Log4j 2.15.0 was incomplete in certain non-default configurations. This could allows attackers with control over Thread Context Map (MDC) input data when the… |
🎯 How it gets exploited (ATT&CK techniques)
Number of CVEs of this technology mapped to each exploitation or primary-impact technique.