PT-2026-67845 · Cvat · Cvat

CVE-2026-65986

·

Published

2026-08-04

·

Updated

2026-08-04

CVSS v4.0

8.5

High

VectorAV:N/AC:L/AT:N/PR:L/UI:P/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions CVAT versions 2.5.0 through 2.66.0
Description An XSS (Cross-Site Scripting) issue exists when the software serves files attached to an annotation guide. An attacker can influence the Content-Type media type, causing the victim's browser to interpret an uploaded file as an HTML page and execute embedded JavaScript instead of treating it as plain data.
Recommendations Update to version 2.67.0.

Exploit

Fix

Unrestricted File Upload

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-65986
GHSA-W6MX-95FF-72CV

Affected Products

Cvat