CVE-2026-44369 Details
Description
CVAT is an open source interactive video and image annotation tool for computer vision. From 2.5.0 to 2.63.0, an attacker who is able to create or edit an annotation guide on a task is able to add malicious JavaScript code, which will then run in the browser of anyone who opens this annotation guide. This code will be able to make arbitrary requests to CVAT with the victim user's privileges. This vulnerability is fixed in 2.64.0.
A stored cross-site scripting vulnerability has been identified in CVAT (Computer Vision Annotation Tool) versions 2.5.0 prior to 2.63.0. This issue allows an attacker with the ability to create or edit an annotation guide on a task to inject malicious JavaScript. The injected script executes in the browser of any user who opens the affected annotation guide, potentially making arbitrary requests to CVAT using the victim's privileges.
Users are advised to upgrade to CVAT version 2.64.0, where this vulnerability has been patched.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed May 13, 2026CISA-ADP
Assessed May 15, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/cvat-ai/cvat/commit/ad9e90003d8234ac7602598b109dc11450321dfc | [email protected] | Source CodeVendor |
| https://github.com/cvat-ai/cvat/security/advisories/GHSA-m2h7-6xqm-p9v5 | [email protected] | AdvisoryRemedyVendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-80 | Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| CVAT | >= 2.5.0, <= 2.63.0 (semver) |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| May 13, 2026 | New CVE Received | [email protected] |
Volerion