PT-2026-79028 · Cvat · Cvat

CVE-2026-73220

·

Published

2026-08-20

·

Updated

2026-08-20

CVSS v4.0

8.5

High

VectorAV:N/AC:L/AT:N/PR:L/UI:P/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions CVAT versions 2.68.0 through 2.69.0
Description An issue exists in the audio-task annotation guide renderer located in cvat-ui/src/audio/components/annotation-page/audio-workspace/top-bar/audio-right-group.tsx where attacker-controlled guide Markdown is passed to MDEditor without the rehype-sanitize plugin. This allows a user with permissions to create or edit an annotation guide to store malicious JavaScript. When another user opens the guide, the script executes, enabling the issuance of arbitrary requests with the victim user's privileges. This is a stored Cross-Site Scripting (XSS) flaw, which occurs when an application stores malicious scripts on a server and later serves them to other users.
Recommendations Update to version 2.70.0.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-73220
GHSA-CHXX-45VM-QHC9

Affected Products

Cvat