XSS Vulnerability in CVAT Open Source Video Annotation Tool
CVE-2026-73220

8.5HIGH

Key Information:

Vendor

Cvat-ai

Status
Vendor
CVE Published:
20 August 2026

What is CVE-2026-73220?

CVAT, an open-source annotation tool for computer vision, is susceptible to a Cross-Site Scripting vulnerability due to improper sanitization of user-controlled Markdown input. Specifically, the annotation guide renderer in versions 2.68.0 through 2.70.0 fails to use the rehype-sanitize plugin, allowing an attacker who can create or edit an annotation guide to inject harmful JavaScript code. This malicious script can execute with the privileges of any user who opens the compromised guide, enabling unauthorized requests to be made on behalf of the victim. This vulnerability has been addressed in version 2.70.0.

Affected Version(s)

cvat >= 2.68.0, < 2.70.0

References

CVSS V4

Score:
8.5
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.