PT-2025-52499 · Intel · Cvat
Roman
·
Published
2025-12-19
·
Updated
2025-12-19
·
CVE-2025-68430
CVSS v4.0
5.3
Medium
| Vector | AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
CVAT versions 2.8.1 through 2.52.0
Description
CVAT is an interactive video and image annotation tool for computer vision. An attacker with an account on a CVAT instance can retrieve the contents of any file system directory accessible to the CVAT server. The exposed information includes the names of contained files and subdirectories, but not the file contents themselves.
Recommendations
Update to version 2.53.0 or later.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Cvat