CVE-2026-47682
CVAT: Missing path-containment validation in multiple entry points allows arbitrary path writes
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
CVAT is an open source interactive video and image annotation tool for computer vision. In versions 1.6.0 through 2.64.0, an attacker with write access to a cloud storage that's been added to a CVAT instance, or ability to add new cloud storages, is able to overwrite arbitrary files on the server's filesystem. This issue has been fixed in version 2.65.0.
| CWE | CWE-22 |
| Vendor | cvat-ai |
| Product | cvat |
| Published | Aug 4, 2026 |
Stay Ahead of the Next One
Get instant alerts for cvat-ai cvat
Be the first to know when new unknown vulnerabilities affecting cvat-ai cvat are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
cvat-ai / cvat
>= 1.6.0< 2.65.0