PT-2026-40818 · Cvat · Cvat
Published
2026-05-13
·
Updated
2026-05-14
·
CVE-2026-44369
CVSS v4.0
8.5
High
| Vector | AV:N/AC:L/AT:N/PR:L/UI:P/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
CVAT versions 2.5.0 through 2.63.0
Description
An attacker with permissions to create or edit an annotation guide on a task can inject malicious JavaScript code. This code executes in the browser of any user who opens the affected guide, allowing the attacker to make arbitrary requests to the system using the victim's privileges. This is a stored cross-site scripting (XSS) issue, where malicious scripts are permanently stored on the server and served to other users.
Recommendations
Update to version 2.64.0.
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Cvat