๐Ÿ” CVE Alert

CVE-2026-47682

UNKNOWN 0.0

CVAT: Missing path-containment validation in multiple entry points allows arbitrary path writes

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

CVAT is an open source interactive video and image annotation tool for computer vision. In versions 1.6.0 through 2.64.0, an attacker with write access to a cloud storage that's been added to a CVAT instance, or ability to add new cloud storages, is able to overwrite arbitrary files on the server's filesystem. This issue has been fixed in version 2.65.0.

CWE CWE-22
Vendor cvat-ai
Product cvat
Published Aug 4, 2026
Stay Ahead of the Next One

Get instant alerts for cvat-ai cvat

Be the first to know when new unknown vulnerabilities affecting cvat-ai cvat are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

cvat-ai / cvat
>= 1.6.0< 2.65.0

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/cvat-ai/cvat/security/advisories/GHSA-6f87-4g86-p9gw github.com: https://github.com/cvat-ai/cvat/commit/6fda3e3285a185ae50039d1af8c8f0e9319b671c