Path Traversal Vulnerability in jsbroks COCO Annotator Product
CVE-2026-7680
5.3MEDIUM
What is CVE-2026-7680?
A path traversal vulnerability has been found in jsbroks COCO Annotator up to version 0.11.1, specifically within an unhandled function located in backend/webserver/api/datasets.py. This flaw allows an attacker to manipulate the argument 'folder' to access arbitrary files on the server. The exploit can be conducted remotely, leading to unauthorized data exposure. The vendor has been notified about this security issue but has not provided any response.
Affected Version(s)
COCO Annotator 0.11.0
COCO Annotator 0.11.1
