Arbitrary Code Execution in Computer Vision Annotation Tool by CVAT Vendor
CVE-2025-23045
What is CVE-2025-23045?
An arbitrary code execution vulnerability exists in the Computer Vision Annotation Tool (CVAT) allowing an attacker with an account to execute code within the Nuclio function container. This affects deployments running serverless functions such as TransT and SiamMask, particularly those utilizing unsafe serialization methods. Administrators are urged to upgrade CVAT to version 2.26.0 or higher to mitigate risks. If upgrading is not possible, it is critical to disable any running instances of the affected functions to prevent exploitation.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
cvat >= 1.1.0, < 2.26.0
References
CVSS V4
Timeline
Vulnerability published
Vulnerability Reserved
