PT-2026-67845 · Cvat · Cvat
CVE-2026-65986
·
Published
2026-08-04
·
Updated
2026-08-04
CVSS v4.0
8.5
High
| Vector | AV:N/AC:L/AT:N/PR:L/UI:P/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X |
Name of the Vulnerable Software and Affected Versions
CVAT versions 2.5.0 through 2.66.0
Description
An XSS (Cross-Site Scripting) issue exists when the software serves files attached to an annotation guide. An attacker can influence the
Content-Type media type, causing the victim's browser to interpret an uploaded file as an HTML page and execute embedded JavaScript instead of treating it as plain data.Recommendations
Update to version 2.67.0.
Exploit
Fix
Unrestricted File Upload
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Cvat