CVE Explorer
CVE-2025-68430
CVAT is an open source interactive video and image annotation tool for computer vision. In versions 2.8.1 through 2.52.0, an attacker with an account on a CVAT instance is able to retrieve the contents of any file system directory accessible to the CVAT server. The exposed information is names of contained files and subdirectories. The contents of files are not accessible. Version 2.53.0 contains a patch. No known workarounds are available.
Known exploited
Not asserted
Disputed
No
Stale source
No
Conflicts
0
Affected products and versions
1 source assertion{"product":"cvat","vendor":"cvat-ai","versions":[{"status":"affected","version":">= 2.8.1, < 2.53.0"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:f711f9bf815685d1ac88fdb21280a7825a8ee2358bd8ed9362e340786edd020c · sha256:d9b6867b531b78ab… · /containers/cna/affected/0
Provider-owned CVSS observations
1 source assertion{"metric":{"attackComplexity":"LOW","attackRequirements":"NONE","attackVector":"NETWORK","baseScore":5.3,"baseSeverity":"MEDIUM","privilegesRequired":"LOW","subAvailabilityImpact":"NONE","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","userInteraction":"NONE","vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N","version":"4.0","vulnAvailabilityImpact":"NONE","vulnConfidentialityImpact":"LOW","vulnIntegrityImpact":"NONE"},"metric_type":"cvssV4_0"}
- cve_program_cvelist_v5cvssurn:baitaphish:normalized-source-record:v2:f711f9bf815685d1ac88fdb21280a7825a8ee2358bd8ed9362e340786edd020c · sha256:d9b6867b531b78ab… · /containers/cna/metrics/0/cvssV4_0
CWE assertions
1 source assertion{"cweId":"CWE-24","description":"CWE-24: Path Traversal: '../filedir'","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:f711f9bf815685d1ac88fdb21280a7825a8ee2358bd8ed9362e340786edd020c · sha256:d9b6867b531b78ab… · /containers/cna/problemTypes/0/descriptions/0
Source references
2 source assertions{"name":"https://github.com/cvat-ai/cvat/commit/2c24ef0c3f8fd94f6c71cff4eafcf11bfcaa5f91","tags":["x_refsource_MISC"],"url":"https://github.com/cvat-ai/cvat/commit/2c24ef0c3f8fd94f6c71cff4eafcf11bfcaa5f91"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:f711f9bf815685d1ac88fdb21280a7825a8ee2358bd8ed9362e340786edd020c · sha256:d9b6867b531b78ab… · /containers/cna/references/1
{"name":"https://github.com/cvat-ai/cvat/security/advisories/GHSA-3g7v-xjh7-xmqx","tags":["x_refsource_CONFIRM"],"url":"https://github.com/cvat-ai/cvat/security/advisories/GHSA-3g7v-xjh7-xmqx"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:f711f9bf815685d1ac88fdb21280a7825a8ee2358bd8ed9362e340786edd020c · sha256:d9b6867b531b78ab… · /containers/cna/references/0
Attribution and limitations
- CVE Program CVEList V5: Reproduce the MITRE copyright designation and CVE license in copies. Source →
Provider severity values are preserved separately. Baitaphish does not convert them into a risk rating, infer affected products, or treat EPSS as observed exploitation.