VYPR

Computer Vision Annotation Tool

by Cvat

CVEs (16)

  • CVE-2021-45046CriKEVDec 14, 2021
    risk 0.87cvss 9.0epss 1.00

    It was found that the fix to address CVE-2021-44228 in Apache Log4j 2.15.0 was incomplete in certain non-default configurations. This could allows attackers with control over Thread Context Map (MDC) input data when the logging configuration uses a non-default Pattern Layout…

  • CVE-2022-31188HigAug 1, 2022
    risk 0.56cvss 8.6epss 0.48

    CVAT is an opensource interactive video and image annotation tool for computer vision. Versions prior to 2.0.0 were found to be subject to a Server-side request forgery (SSRF) vulnerability. Validation has been added to urls used in the affected code path in version 2.0.0. Users…

  • CVE-2026-58373MedJun 30, 2026
    risk 0.00cvss 4.3epss 0.00

    CVAT before 2.69.0 contains an improper authorization vulnerability in QualityReportViewSet.get_queryset that allows authenticated attackers to enumerate quality report identifiers belonging to other organizations by exploiting a missing check_object_permissions call on the…

  • CVE-2026-23526HigJan 21, 2026
    risk 0.00cvss 8.8epss 0.00

    CVAT is an open source interactive video and image annotation tool for computer vision. In versions 1.0.0 through 2.54.0, users that have the staff status may freely change their permissions, including giving themselves superuser status and joining the admin group, which gives…

  • CVE-2026-23516MedJan 21, 2026
    risk 0.00cvss 5.4epss 0.00

    CVAT is an open source interactive video and image annotation tool for computer vision. In versions 2.2.0 through 2.54.0, an attacker is able to execute arbitrary JavaScript in a victim user's CVAT UI session, provided that they are able to create a maliciously crafted label in…

  • CVE-2025-68430MedDec 19, 2025
    risk 0.00cvss 4.3epss 0.00

    CVAT is an open source interactive video and image annotation tool for computer vision. In versions 2.8.1 through 2.52.0, an attacker with an account on a CVAT instance is able to retrieve the contents of any file system directory accessible to the CVAT server. The exposed…

  • CVE-2025-54573MedJul 30, 2025
    risk 0.00cvss 4.3epss 0.00

    CVAT is an open source interactive video and image annotation tool for computer vision. In versions 1.1.0 through 2.41.0, email verification was not enforced when using Basic HTTP Authentication. As a result, users could create accounts using fake email addresses and use the…

  • CVE-2025-49135MedJun 25, 2025
    risk 0.00cvss 6.5epss 0.00

    CVAT is an open source interactive video and image annotation tool for computer vision. Versions 2.2.0 through 2.39.0 have no validation during the import process of a project or task backup to check that the filename specified in the query parameter refers to a TUS-uploaded…

  • CVE-2025-48381MedMay 30, 2025
    risk 0.00cvss 4.3epss 0.00

    Computer Vision Annotation Tool (CVAT) is an interactive video and image annotation tool for computer vision. In versions starting from 2.4.0 to before 2.38.0, an authenticated CVAT user may be able to retrieve the IDs and names of all tasks, projects, labels, and the IDs of all…

  • CVE-2025-23045CriJan 28, 2025
    risk 0.00cvss 9.8epss 0.00

    Computer Vision Annotation Tool (CVAT) is an interactive video and image annotation tool for computer vision. An attacker with an account on an affected CVAT instance is able to run arbitrary code in the context of the Nuclio function container. This vulnerability affects CVAT…

  • CVE-2024-47172MedSep 30, 2024
    risk 0.00cvss 5.4epss 0.00

    Computer Vision Annotation Tool (CVAT) is an interactive video and image annotation tool for computer vision. An attacker with a CVAT account may retrieve certain information about any project, task, job or membership resource on the CVAT instance. The information exposed in…

  • CVE-2024-47064MedSep 30, 2024
    risk 0.00cvss 6.1epss 0.00

    Computer Vision Annotation Tool (CVAT) is an interactive video and image annotation tool for computer vision. If an attacker can trick a logged-in CVAT user into visiting a maliciously-constructed URL, they can initiate any API calls on that user's behalf. This gives the…

  • CVE-2024-47063MedSep 30, 2024
    risk 0.00cvss 6.1epss 0.00

    Computer Vision Annotation Tool (CVAT) is an interactive video and image annotation tool for computer vision. If a malicious CVAT user with permissions to either create a task, or edit an existing task can trick another logged-in user into visiting a maliciously-constructed URL,…

  • CVE-2024-45393MedSep 10, 2024
    risk 0.00cvss 6.4epss 0.00

    Computer Vision Annotation Tool (CVAT) is an interactive video and image annotation tool for computer vision. An attacker with a CVAT account can access webhook delivery information for any webhook registered on the CVAT instance, including that of other users. For each…

  • CVE-2024-37306HigJun 13, 2024
    risk 0.00cvss 7.1epss 0.00

    Computer Vision Annotation Tool (CVAT) is an interactive video and image annotation tool for computer vision. Starting in version 2.2.0 and prior to version 2.14.3, if an attacker can trick a logged-in CVAT user into visiting a malicious URL, they can initiate a dataset export…

  • CVE-2024-37164HigJun 13, 2024
    risk 0.00cvss 7.1epss 0.00

    Computer Vision Annotation Tool (CVAT) is an interactive video and image annotation tool for computer vision. CVAT allows users to supply custom endpoint URLs for cloud storages based on Amazon S3 and Azure Blob Storage. Starting in version 2.1.0 and prior to version 2.14.3, an…