CVE 5.3 MEDIUM

CVAT vulnerable to directory traversal via mounted share listing_CVE-2025-68430

5.3 / 10
MEDIUM
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N

Description

CVAT is an open source interactive video and image annotation tool for computer vision. In versions 2.8.1 through 2.52.0, an attacker with an account on a CVAT instance is able to retrieve the contents of any file system directory accessible to the CVAT server. The exposed information is names of contained files and subdirectories. The contents of files are not accessible. Version 2.53.0 contains a patch. No known workarounds are available.

Basic Information

ID CVE-2025-68430
Source GitHub_M
Published Dec 19, 2025 at 17:11
Modified Dec 19, 2025 at 17:59

Affected Product

Vendor cvat-ai
Product cvat
Version >= 2.8.1, < 2.53.0
Affected Versions cvat-ai cvat >= 2.8.1, < 2.53.0

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.