CVE-2026-73220

Source
https://cve.org/CVERecord?id=CVE-2026-73220
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-73220.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-73220
Aliases
  • GHSA-chxx-45vm-qhc9
Published
2026-08-20T14:32:52.680Z
Modified
2026-08-22T03:58:18.973835318Z
Severity
  • 8.5 (High) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N CVSS Calculator
Summary
CVAT: Stored XSS via annotation guides in audio tasks
Details

CVAT is an open source interactive video and image annotation tool for computer vision. From 2.68.0 until 2.70.0, the audio-task annotation guide renderer in cvat-ui/src/audio/components/annotation-page/audio-workspace/top-bar/audio-right-group.tsx passes attacker-controlled guide Markdown to MDEditor without the rehype-sanitize plugin. A user who can create or edit an annotation guide can store malicious JavaScript that executes when another user opens the guide. The script can issue arbitrary CVAT requests with the victim user's privileges. This issue is fixed in version 2.70.0.

Database specific
{
    "cwe_ids": [
        "CWE-80"
    ],
    "cna_assigner": "GitHub_M",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/73xxx/CVE-2026-73220.json"
}
References

Affected packages

Git / github.com/cvat-ai/cvat

Affected ranges

Type
GIT
Repo
https://github.com/cvat-ai/cvat
Events
Database specific
Show details
{
    "source": [
        "AFFECTED_FIELD",
        "REFERENCES"
    ],
    "extracted_events": [
        {
            "introduced": "2.68.0"
        },
        {
            "fixed": "2.70.0"
        }
    ]
}

Affected versions

v2.*
v2.68.0
v2.69.0

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-73220.json"