CVE-2026-23516

CVAT is an open source interactive video and image annotation tool for computer vision. In versions 2.2.0 through 2.54.0, an attacker is able to execute arbitrary JavaScript in a victim user's CVAT UI session, provided that they are able to create a maliciously crafted label in a CVAT task or project, then get the victim user to either edit that label, or view a shape that refers to that label; and/or get the victim user to upload a maliciously crafted SVG image when configuring a skeleton. This gives the attacker temporary access to all CVAT resources that the victim user can access. Version 2.55.0 fixes the issue.
Configurations

Configuration 1 (hide)

cpe:2.3:a:cvat:computer_vision_annotation_tool:*:*:*:*:*:*:*:*

History

17 Jun 2026, 10:21

Type Values Removed Values Added
Summary
  • (es) CVAT es una herramienta de anotación de video e imagen interactiva de código abierto para visión artificial. En las versiones 2.2.0 a la 2.54.0, un atacante es capaz de ejecutar JavaScript arbitrario en la sesión de la interfaz de usuario de CVAT de un usuario víctima, siempre que sea capaz de crear una etiqueta creada maliciosamente en una tarea o proyecto de CVAT, luego lograr que el usuario víctima edite esa etiqueta, o vea una forma que se refiera a esa etiqueta; y/o lograr que el usuario víctima cargue una imagen SVG creada maliciosamente al configurar un esqueleto. Esto le da al atacante acceso temporal a todos los recursos de CVAT a los que el usuario víctima puede acceder. La versión 2.55.0 corrige el problema.

20 Feb 2026, 20:08

Type Values Removed Values Added
CPE cpe:2.3:a:cvat:cvat:*:*:*:*:*:*:*:* cpe:2.3:a:cvat:computer_vision_annotation_tool:*:*:*:*:*:*:*:*
References () https://github.com/cvat-ai/cvat/security/advisories/GHSA-3m7p-wx65-c7mp - Third Party Advisory, Patch () https://github.com/cvat-ai/cvat/security/advisories/GHSA-3m7p-wx65-c7mp - Patch, Third Party Advisory
First Time Cvat computer Vision Annotation Tool

02 Feb 2026, 15:15

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 5.4
CWE CWE-79
First Time Cvat
Cvat cvat
CPE cpe:2.3:a:cvat:cvat:*:*:*:*:*:*:*:*
References () https://github.com/cvat-ai/cvat/commit/40800707fe39e3ff76c8d036eb953eb12d764e70 - () https://github.com/cvat-ai/cvat/commit/40800707fe39e3ff76c8d036eb953eb12d764e70 - Patch
References () https://github.com/cvat-ai/cvat/security/advisories/GHSA-3m7p-wx65-c7mp - () https://github.com/cvat-ai/cvat/security/advisories/GHSA-3m7p-wx65-c7mp - Third Party Advisory, Patch

21 Jan 2026, 22:15

Type Values Removed Values Added
New CVE

Information

Published : 2026-01-21 22:15

Updated : 2026-06-17 10:21


NVD link : CVE-2026-23516

Mitre link : CVE-2026-23516

CVE.ORG link : CVE-2026-23516


JSON object : View

Products Affected

cvat

  • computer_vision_annotation_tool
CWE
CWE-83

Improper Neutralization of Script in Attributes in a Web Page

CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')