Impact
The vulnerability allows an attacker with write access to cloud storage or the ability to add new cloud storages to CVAT to overwrite arbitrary files on the server’s filesystem. This can lead to compromise of configuration, binaries, or other critical files, creating an opportunity for further exploitation. The weakness corresponds to CWE‑22 and can affect confidentiality, integrity, and availability of the system.
Affected Systems
CVAT, an open‑source interactive video and image annotation tool maintained by cvat‑ai. Versions 1.6.0 through 2.64.0 are affected. The security fix was incorporated in 2.65.0.
Risk and Exploitability
The CVSS score of 7.1 indicates high severity; no EPSS score is available, so the current exploitation probability is uncertain, and the vulnerability is not listed in the CISA KEV catalog. The attack seems to require that the attacker already has some level of write access to a cloud storage connected to the CVAT instance or the privilege to add new cloud storages. By passing a crafted file path, the attacker can overwrite any file on the server, potentially allowing the execution of arbitrary code if core binaries or configuration files are replaced. Because this write privilege is typically granted to trusted users, the risk is moderate to high in environments where cloud storages are broadly accessible.
OpenCVE Enrichment