PatchSiren

cvat-ai CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH cvat-ai CVE published 2026-08-04

CVE-2026-65986

The CVAT tool, used for computer vision tasks, contains a XSS vulnerability in versions 2.5.0 through 2.66.0. This vulnerability is accessible through annotation guide assets and can be exploited by influencing the media type of uploaded files. The issue has been fixed in version 2.67.0. Organizations using CVAT should be aware of this vulnerability and take steps to update to a patched version. The vulne [truncated]

HIGH cvat-ai CVE published 2026-08-04

CVE-2026-47682

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-04T20:16:51.747Z and has not been modified since then. CVAT versions 1.6.0 through 2.64.0 are vulnerable to arbitrary file overwrites due to improper handling of cloud storage. An attacker with write access to a cloud storage added to a CVAT instance or ability to add new cloud storages can overwrit [truncated]

MEDIUM cvat-ai CVE published 2026-06-30

CVE-2026-58373

The Computer Vision Annotation Tool (CVAT) contains an improper authorization vulnerability, tracked as CVE-2026-58373, affecting CVAT versions before 2.69.0. This issue allows authenticated attackers to enumerate quality report identifiers belonging to other organizations by exploiting a missing check_object_permissions call on the parent_id query parameter of the quality reports API endpoint. The vulner [truncated]