Inconsistent Task Definition in CVAT by CVAT.ai
CVE-2026-73219

5.3MEDIUM

Key Information:

Vendor

Cvat-ai

Status
Vendor
CVE Published:
11 August 2026

What is CVE-2026-73219?

An inconsistency in task management within the CVAT tool allows a user with write access to disrupt automatic annotation processes. Specifically, by submitting a batch automatic annotation request with mismatched task and job IDs, a user can effectively block the automatic annotation capabilities for other tasks. This abnormal behavior occurs due to the way task IDs are utilized to manage active request slots in the system. This issue was resolved in version 2.72.0, which ensures consistent task ID validation, thereby preventing unauthorized interference with annotation jobs.

Affected Version(s)

cvat >= 2.17.0, < 2.72.0

References

CVSS V4

Score:
5.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.