Path traversal in Computer Vision Annotation Tool (CVAT) - CVE-2025-68430
Published: December 23, 2025
Vulnerability identifier: #VU120253
CSH Severity: Low
CVSS v4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2025-68430
CWE-ID: CWE-22
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote user to perform directory traversal attacks.
The vulnerability exists due to input validation error when processing directory traversal sequences in mounted share listing. A remote user can view contents of any directory accessible to the CVAT server without the possibility to view files' contents.
Affected software
Computer Vision Annotation Tool (CVAT)
How to mitigate CVE-2025-68430
Install updates from vendor's website.
Computer Vision Annotation Tool (CVAT) - update to 2.53.0