Security: cvat-ai/cvat
Security Advisories
View information about security vulnerabilities from this repository's maintainers.
-
Email verification bypass by use of basic authenticationGHSA-fxgh-m76j-242q published
Jul 30, 2025 by nmanovicModerate -
Information disclosure via browsable APIGHSA-7484-2gfm-852p published
May 28, 2025 by SpecLadModerate -
Missing validation for in-progress backup upload namesGHSA-frpr-5w6q-hh4f published
Jun 25, 2025 by SpecLadModerate -
Remote code execution via tracker Nuclio functionsGHSA-wq36-mxf8-hv62 published
Jan 28, 2025 by SpecLadHigh -
Broken access control in several PATCH endpointsGHSA-gxhm-hg65-5gh2 published
Sep 30, 2024 by SpecLadModerate -
Stored XSS via the quality report data endpointGHSA-2c85-39cc-2px9 published
Sep 30, 2024 by SpecLadHigh -
Reflected XSS via request endpointsGHSA-hp6c-f34j-qjj7 published
Sep 30, 2024 by SpecLadHigh -
Missing authorization for endpoints related to webhook deliveriesGHSA-p3c9-m7jr-jxxj published
Sep 10, 2024 by SpecLadModerate -
SSRF via custom cloud storage endpointsGHSA-q684-4jjh-83g6 published
Jun 13, 2024 by SpecLadHigh -
Export and backup-related API endpoints are susceptible to CSRFGHSA-jpf9-646h-4px7 published
Jun 13, 2024 by SpecLadHigh