PT-2026-79028 · Cvat · Cvat
CVE-2026-73220
·
Published
2026-08-20
·
Updated
2026-08-20
CVSS v4.0
8.5
High
| Vector | AV:N/AC:L/AT:N/PR:L/UI:P/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
CVAT versions 2.68.0 through 2.69.0
Description
An issue exists in the audio-task annotation guide renderer located in
cvat-ui/src/audio/components/annotation-page/audio-workspace/top-bar/audio-right-group.tsx where attacker-controlled guide Markdown is passed to MDEditor without the rehype-sanitize plugin. This allows a user with permissions to create or edit an annotation guide to store malicious JavaScript. When another user opens the guide, the script executes, enabling the issuance of arbitrary requests with the victim user's privileges. This is a stored Cross-Site Scripting (XSS) flaw, which occurs when an application stores malicious scripts on a server and later serves them to other users.Recommendations
Update to version 2.70.0.
Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Cvat