PT-2026-40818 · Cvat · Cvat

Published

2026-05-13

·

Updated

2026-05-14

·

CVE-2026-44369

CVSS v4.0

8.5

High

VectorAV:N/AC:L/AT:N/PR:L/UI:P/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions CVAT versions 2.5.0 through 2.63.0
Description An attacker with permissions to create or edit an annotation guide on a task can inject malicious JavaScript code. This code executes in the browser of any user who opens the affected guide, allowing the attacker to make arbitrary requests to the system using the victim's privileges. This is a stored cross-site scripting (XSS) issue, where malicious scripts are permanently stored on the server and served to other users.
Recommendations Update to version 2.64.0.

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2026-44369

Affected Products

Cvat