Path Traversal Vulnerability in jsbroks COCO Annotator Product
CVE-2026-7680

5.3MEDIUM

Key Information:

Vendor

Jsbroks

Vendor
CVE Published:
3 May 2026

What is CVE-2026-7680?

A path traversal vulnerability has been found in jsbroks COCO Annotator up to version 0.11.1, specifically within an unhandled function located in backend/webserver/api/datasets.py. This flaw allows an attacker to manipulate the argument 'folder' to access arbitrary files on the server. The exploit can be conducted remotely, leading to unauthorized data exposure. The vendor has been notified about this security issue but has not provided any response.

Affected Version(s)

COCO Annotator 0.11.0

COCO Annotator 0.11.1

References

CVSS V4

Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

nmmorette (VulDB User)
VulDB CNA Team
.