PT-2026-40818 · Cvat · Cvat

CVE-2026-44369

·

Published

2026-05-13

·

Updated

2026-05-14

CVSS v4.0

8.5

High

VectorAV:N/AC:L/AT:N/PR:L/UI:P/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions CVAT versions 2.5.0 through 2.63.0
Description An attacker with permissions to create or edit an annotation guide on a task can inject malicious JavaScript code. This code executes in the browser of any user who opens the affected guide, allowing the attacker to make arbitrary requests to the system using the victim's privileges. This is a stored cross-site scripting (XSS) issue, where malicious scripts are permanently stored on the server and served to other users.
Recommendations Update to version 2.64.0.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-44369
GHSA-M2H7-6XQM-P9V5

Affected Products

Cvat