Security: cvat-ai/cvat
Security Advisories
View information about security vulnerabilities from this repository's maintainers.
-
Denial of service with regards to automatic annotationGHSA-7xhx-3q27-xvcx published
Aug 3, 2026 by SpecLadModerate -
Insufficient authorization logic in endpoints related to lambda requestsGHSA-m7p7-6w4m-886p published
Aug 3, 2026 by SpecLadModerate -
Stored XSS via annotation guides in audio tasksGHSA-chxx-45vm-qhc9 published
Jul 16, 2026 by SpecLadHigh -
Stored XSS via annotation guide assetsGHSA-w6mx-95ff-72cv published
Jun 3, 2026 by SpecLadHigh -
Stored XSS via annotation guidesGHSA-m2h7-6xqm-p9v5 published
Apr 30, 2026 by SpecLadHigh -
Multiple path traversal vulnerabilities allowing arbitrary path writesGHSA-6f87-4g86-p9gw published
May 21, 2026 by SpecLadHigh -
Privilege escalation of users with staff statusGHSA-7pvv-w55f-qmw7 published
Jan 20, 2026 by SpecLadHigh -
XSS via skeleton SVG imagesGHSA-3m7p-wx65-c7mp published
Jan 20, 2026 by SpecLadHigh -
Directory traversal via mounted share listingGHSA-3g7v-xjh7-xmqx published
Dec 19, 2025 by SpecLadModerate -
Mounted share file overwrite via crafted requestGHSA-x396-w86c-gf6w published
Nov 6, 2025 by SpecLadModerate