« Back to list

Cvat

Cvat Computer Vision Annotation Tool: vulnerabilities and CVEs

Cvat Computer Vision Annotation Tool has 16 published vulnerabilities, 4 of them in the last 12 months. 2 are rated critical and 1 are listed by CISA as actively exploited.

CVEs16
Last 12 months4
Critical2
Actively exploited1

All vulnerabilities in the catalogue →⭐ Follow this technology

🔴 Actively exploited (CISA KEV)

CVESeverityEPSSActive exploitationPublishedDescription
CVE-2021-45046Critical (9)100%⚠ Active exploitationDec 14, 2021
It was found that the fix to address CVE-2021-44228 in Apache Log4j 2.15.0 was incomplete in certain non-default configurations. This could allows attackers with control over Thread Context Map (MDC) input data when the…

Latest vulnerabilities

CVESeverityEPSSActive exploitationPublishedDescription
CVE-2026-58373Medium (5.3)0.34%—Jun 30, 2026
CVAT before 2.69.0 contains an improper authorization vulnerability in QualityReportViewSet.get_queryset that allows authenticated attackers to enumerate quality report identifiers belonging to other organizations by…
CVE-2026-23526High (8.5)0.29%—Jan 21, 2026
CVAT is an open source interactive video and image annotation tool for computer vision. In versions 1.0.0 through 2.54.0, users that have the staff status may freely change their permissions, including giving themselves…
CVE-2026-23516High (8.6)0.17%—Jan 21, 2026
CVAT is an open source interactive video and image annotation tool for computer vision. In versions 2.2.0 through 2.54.0, an attacker is able to execute arbitrary JavaScript in a victim user's CVAT UI session, provided…
CVE-2025-68430Medium (5.3)0.29%—Dec 19, 2025
CVAT is an open source interactive video and image annotation tool for computer vision. In versions 2.8.1 through 2.52.0, an attacker with an account on a CVAT instance is able to retrieve the contents of any file…
CVE-2025-54573Medium (6.5)0.27%—Jul 30, 2025
CVAT is an open source interactive video and image annotation tool for computer vision. In versions 1.1.0 through 2.41.0, email verification was not enforced when using Basic HTTP Authentication. As a result, users…
CVE-2025-49135Medium (5.3)0.30%—Jun 25, 2025
CVAT is an open source interactive video and image annotation tool for computer vision. Versions 2.2.0 through 2.39.0 have no validation during the import process of a project or task backup to check that the filename…
CVE-2025-48381Medium (5.3)0.28%—May 30, 2025
Computer Vision Annotation Tool (CVAT) is an interactive video and image annotation tool for computer vision. In versions starting from 2.4.0 to before 2.38.0, an authenticated CVAT user may be able to retrieve the IDs…
CVE-2025-23045High (8.7)0.50%—Jan 28, 2025
Computer Vision Annotation Tool (CVAT) is an interactive video and image annotation tool for computer vision. An attacker with an account on an affected CVAT instance is able to run arbitrary code in the context of the…
CVE-2024-47172Medium (5.4)0.26%—Sep 30, 2024
Computer Vision Annotation Tool (CVAT) is an interactive video and image annotation tool for computer vision. An attacker with a CVAT account may retrieve certain information about any project, task, job or membership…
CVE-2024-47064Medium (6.3)0.31%—Sep 30, 2024
Computer Vision Annotation Tool (CVAT) is an interactive video and image annotation tool for computer vision. If an attacker can trick a logged-in CVAT user into visiting a maliciously-constructed URL, they can initiate…
CVE-2024-47063Medium (6.2)0.30%—Sep 30, 2024
Computer Vision Annotation Tool (CVAT) is an interactive video and image annotation tool for computer vision. If a malicious CVAT user with permissions to either create a task, or edit an existing task can trick another…
CVE-2024-45393Medium (6.4)0.24%—Sep 10, 2024
Computer Vision Annotation Tool (CVAT) is an interactive video and image annotation tool for computer vision. An attacker with a CVAT account can access webhook delivery information for any webhook registered on the…
CVE-2024-37306High (7.1)0.21%—Jun 13, 2024
Computer Vision Annotation Tool (CVAT) is an interactive video and image annotation tool for computer vision. Starting in version 2.2.0 and prior to version 2.14.3, if an attacker can trick a logged-in CVAT user into…
CVE-2024-37164High (8.5)0.35%—Jun 13, 2024
Computer Vision Annotation Tool (CVAT) is an interactive video and image annotation tool for computer vision. CVAT allows users to supply custom endpoint URLs for cloud storages based on Amazon S3 and Azure Blob…
CVE-2022-31188Critical (9.8)49%—Aug 1, 2022
CVAT is an opensource interactive video and image annotation tool for computer vision. Versions prior to 2.0.0 were found to be subject to a Server-side request forgery (SSRF) vulnerability. Validation has been added to…
CVE-2021-45046Critical (9)100%⚠ Active exploitationDec 14, 2021
It was found that the fix to address CVE-2021-44228 in Apache Log4j 2.15.0 was incomplete in certain non-default configurations. This could allows attackers with control over Thread Context Map (MDC) input data when the…

🎯 How it gets exploited (ATT&CK techniques)

  1. T1059.007 JavaScript1
  2. T1190 Exploit Public-Facing Application1

Number of CVEs of this technology mapped to each exploitation or primary-impact technique.

Other products by Cvat