Path traversal in Computer Vision Annotation Tool (CVAT) - CVE-2025-68430

 

Path traversal in Computer Vision Annotation Tool (CVAT) - CVE-2025-68430

Published: December 23, 2025


Vulnerability identifier: #VU120253
CSH Severity: Low
CVSS v4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2025-68430
CWE-ID: CWE-22
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to perform directory traversal attacks.

The vulnerability exists due to input validation error when processing directory traversal sequences in mounted share listing. A remote user can view contents of any directory accessible to the CVAT server without the possibility to view files' contents. 


Affected software

Computer Vision Annotation Tool (CVAT)

How to mitigate CVE-2025-68430

Install updates from vendor's website.

Computer Vision Annotation Tool (CVAT) - update to 2.53.0

External References

Related Security Bulletins