CVE-2026-47682

Source
https://cve.org/CVERecord?id=CVE-2026-47682
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-47682.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-47682
Aliases
  • GHSA-6f87-4g86-p9gw
Published
2026-08-04T20:00:49.754Z
Modified
2026-08-12T03:51:15.187583941Z
Severity
  • 7.1 (High) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N CVSS Calculator
Summary
CVAT: Missing path-containment validation in multiple entry points allows arbitrary path writes
Details

CVAT is an open source interactive video and image annotation tool for computer vision. In versions 1.6.0 through 2.64.0, an attacker with write access to a cloud storage that's been added to a CVAT instance, or ability to add new cloud storages, is able to overwrite arbitrary files on the server's filesystem. This issue has been fixed in version 2.65.0.

Database specific
{
    "cwe_ids": [
        "CWE-22"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/47xxx/CVE-2026-47682.json",
    "cna_assigner": "GitHub_M",
    "unresolved_ranges": [
        {
            "extracted_events": [
                {
                    "introduced": ">= 1.6.0< 2.65.0"
                },
                {
                    "last_affected": ">= 1.6.0< 2.65.0"
                }
            ],
            "source": "AFFECTED_FIELD"
        }
    ]
}
References

Affected packages

Git / github.com/cvat-ai/cvat

Affected ranges

Type
GIT
Repo
https://github.com/cvat-ai/cvat
Events
Database specific
Show details
{
    "source": [
        "DESCRIPTION",
        "REFERENCES"
    ],
    "extracted_events": [
        {
            "introduced": "1.6.0"
        },
        {
            "fixed": "2.64.0"
        }
    ]
}

Affected versions

v1.*
v1.6.0
v1.7.0
v2.*
v2.0.0
v2.1.0
v2.10.0
v2.10.1
v2.10.2
v2.10.3
v2.11.0
v2.11.1
v2.11.2
v2.11.3
v2.12.0
v2.12.1
v2.13.0
v2.14.0
v2.14.1
v2.14.2
v2.14.3
v2.14.4
v2.15.0
v2.16.0
v2.16.1
v2.16.2
v2.16.3
v2.17.0
v2.18.0
v2.19.0
v2.19.1
v2.2.0
v2.20.0
v2.21.0
v2.21.1
v2.21.2
v2.21.3
v2.22.0
v2.23.0
v2.23.1
v2.24.0
v2.25.0
v2.26.0
v2.26.1
v2.27.0
v2.28.0
v2.29.0
v2.3.0
v2.30.0
v2.31.0
v2.32.0
v2.33.0
v2.34.0
v2.35.0
v2.36.0
v2.37.0
v2.38.0
v2.39.0
v2.4.0
v2.4.1
v2.4.2
v2.4.3
v2.4.4
v2.4.5
v2.4.6
v2.4.7
v2.4.8
v2.4.9
v2.40.0
v2.40.1
v2.41.0
v2.42.0
v2.43.0
v2.44.0
v2.44.1
v2.44.3
v2.45.0
v2.46.0
v2.46.1
v2.47.0
v2.48.0
v2.48.1
v2.49.0
v2.5.0
v2.5.1
v2.5.2
v2.50.0
v2.51.0
v2.52.0
v2.53.0
v2.54.0
v2.55.0
v2.56.0
v2.56.1
v2.57.0
v2.58.0
v2.59.0
v2.59.1
v2.6.0
v2.6.1
v2.6.2
v2.60.0
v2.61.0
v2.62.0
v2.63.0
v2.7.0
v2.7.1
v2.7.2
v2.7.3
v2.7.4
v2.7.5
v2.7.6
v2.8.0
v2.8.1
v2.8.2
v2.9.0
v2.9.1
v2.9.2

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-47682.json"