CVAT is a narrowly focused computer-vision annotation tool that supports collaborative data labeling and model training pipelines, but its role in ML and data-processing workflows makes it a target for supply-chain and training-data compromise. Vulnerabilities affecting the product skew toward serious outcomes and frequently acquire public exploit code, with a moderate tendency toward confirmed in-the-wild exploitation; the recurring weakness classes—including cross-site scripting, server-side request forgery, authorization bypass, cross-site request forgery, and untrusted deserialization—reflect both the web-application attack surface and the data-handling trust boundaries inherent to annotation and model-preparation systems. Defenders deploying this tool should treat it as a network-boundary appliance, enforce strict authentication and input filtering, and monitor for supply-chain vectors; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Cvat over time
Signals from CVEs in this vendor scope (16 CVEs).
16 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-45046CRITICAL It was found that the fix to address CVE-2021-44228 in Apache Log4j 2.15.0 was incomplete in certain non-default configurations. This could allows attackers with control over Threa | Dec 14, 2021 | 9.0 | 98 | YES | YES |
CVE-2022-31188CRITICAL CVAT is an opensource interactive video and image annotation tool for computer vision. Versions prior to 2.0.0 were found to be subject to a Server-side request forgery (SSRF) vuln | Aug 1, 2022 | 9.8 | 68 | NO | YES |
CVE-2026-23526HIGH CVAT is an open source interactive video and image annotation tool for computer vision. In versions 1.0.0 through 2.54.0, users that have the staff status may freely change their p | Jan 21, 2026 | 8.8 | 27 | NO | NO |
CVE-2025-23045CRITICAL Computer Vision Annotation Tool (CVAT) is an interactive video and image annotation tool for computer vision. An attacker with an account on an affected CVAT instance is able to ru | Jan 28, 2025 | 9.8 | 27 | NO | NO |
CVE-2026-58373MEDIUM CVAT before 2.69.0 contains an improper authorization vulnerability in QualityReportViewSet.get_queryset that allows authenticated attackers to enumerate quality report identifiers | Jun 30, 2026 | 4.3 | 25 | NO | NO |
CVE-2026-23516MEDIUM CVAT is an open source interactive video and image annotation tool for computer vision. In versions 2.2.0 through 2.54.0, an attacker is able to execute arbitrary JavaScript in a v | Jan 21, 2026 | 5.4 | 23 | NO | NO |
CVE-2024-37164HIGH Computer Vision Annotation Tool (CVAT) is an interactive video and image annotation tool for computer vision. CVAT allows users to supply custom endpoint URLs for cloud storages ba | Jun 13, 2024 | 8.5 | 23 | NO | NO |
CVE-2025-54573MEDIUM CVAT is an open source interactive video and image annotation tool for computer vision. In versions 1.1.0 through 2.41.0, email verification was not enforced when using Basic HTTP | Jul 30, 2025 | 6.5 | 22 | NO | NO |
CVE-2024-37306HIGH Computer Vision Annotation Tool (CVAT) is an interactive video and image annotation tool for computer vision. Starting in version 2.2.0 and prior to version 2.14.3, if an attacker | Jun 13, 2024 | 7.1 | 20 | NO | NO |
CVE-2025-49135MEDIUM CVAT is an open source interactive video and image annotation tool for computer vision. Versions 2.2.0 through 2.39.0 have no validation during the import process of a project or t | Jun 25, 2025 | 6.5 | 19 | NO | NO |
Signals from CVEs in this vendor scope (16 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Cvat.
Media articles that mention a CVE ID that affects a product developed by Cvat — matched by CVE ID, not by vendor name.