Unrated severityNVD Advisory· Published Aug 4, 2026
CVAT: Missing path-containment validation in multiple entry points allows arbitrary path writes
CVE-2026-47682
Description
CVAT is an open source interactive video and image annotation tool for computer vision. In versions 1.6.0 through 2.64.0, an attacker with write access to a cloud storage that's been added to a CVAT instance, or ability to add new cloud storages, is able to overwrite arbitrary files on the server's filesystem. This issue has been fixed in version 2.65.0.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
1Patches
Vulnerability mechanics
References
2- github.com/cvat-ai/cvat/commit/6fda3e3285a185ae50039d1af8c8f0e9319b671cmitrex_refsource_MISC
- github.com/cvat-ai/cvat/security/advisories/GHSA-6f87-4g86-p9gwmitrex_refsource_CONFIRM
News mentions
0No linked articles in our index yet.