PT-2025-26837 · Cvat · Cvat

Speclad

·

Publicado

2025-06-25

·

Atualizado

2025-06-25

·

CVE-2025-49135

CVSS v3.1

6.5

Média

VetorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions: CVAT versions 2.2.0 through 2.39.0
Description: CVAT is an open source interactive video and image annotation tool for computer vision. The issue arises from the lack of validation during the import process of a project or task backup, allowing an attacker with a CVAT account and a user role to potentially access and steal data by creating projects or tasks using files belonging to other users, if they know the filenames of those uploads. This issue does not affect annotation or dataset TUS uploads.
Recommendations: For CVAT versions 2.2.0 through 2.39.0, upgrade to CVAT 2.40.0 or a later version to receive a patch. As a temporary workaround, consider restricting access to the import process of project or task backups to minimize the risk of exploitation.

Exploit

Correção

IDOR

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2025-49135
GHSA-FRPR-5W6Q-HH4F

Produtos afetados

Cvat