Deserialization of Untrusted Data in Computer Vision Annotation Tool (CVAT) - CVE-2025-23045

 

Deserialization of Untrusted Data in Computer Vision Annotation Tool (CVAT) - CVE-2025-23045

Published: January 28, 2025 / Updated: May 21, 2026


Vulnerability identifier: #VU132049
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2025-23045
CWE-ID: CWE-502
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to execute arbitrary code.

The vulnerability exists due to deserialization of untrusted data in tracker Nuclio functions when restoring serialized tracking state. A remote user can supply crafted serialized state data to execute arbitrary code.

This affects deployments running tracker functions such as TransT and SiamMask, and may also affect custom tracker functions depending on how they handle state serialization.


Affected software

Computer Vision Annotation Tool (CVAT)

How to mitigate CVE-2025-23045

Install security update from vendor's website.

Computer Vision Annotation Tool (CVAT) - update to 2.26.0

External References

Related Security Bulletins