CVE-2026-73220
CVAT is an open source interactive video and image annotation tool for computer vision. From 2.68.0 until 2.70.0, the audio-task annotation guide renderer in cvat-ui/src/audio/components/annotation-page/audio-workspace/top-bar/audio-right-group.tsx passes attacker-controlled guide Markdown to MDEditor without the rehype-sanitize plugin. A user who can create or edit an annotation guide can store malicious JavaScript that executes when another user opens the guide. The script can issue arbitrary CVAT requests with the victim user's privileges. This issue is fixed in version 2.70.0.
Scoring
- Severity
- HIGH
- CVSS base score
- 8.5
- CVSS vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N
- EPSS probability
- 0.28%
- CWE
- CWE-80
- Published
- 2026-08-20
- Last modified
- 2026-08-20
Affected products
- cvat-ai cvat
Weakness type
Related vulnerabilities
- CVE-2026-52774 — Reflected XSS via Unescaped `id` Parameter in Bazar Widget HTML Attributes in YesWiki
- CVE-2026-52773 — Reflected XSS via Unescaped Archived-Revision `time` Parameter in `handlers/page/show.php` in YesWiki
- CVE-2026-32773 — Apache Spark: XSS Vulnerability in Spark Web 3.5.4
- CVE-2026-82838 — Default webserver configuration with incorrect CSP
- CVE-2026-55696 — PrivateBin: Stored Cross-Side-Scripting (XSS) vulnerability in attachment download link via dangerous MIME types with required user-interaction
- CVE-2026-5218 — HTML Injection in Softtr's E-Commerce Pack
- CVE-2026-5389 — justhtml before 1.13.0 XSS via code fence breakout
- CVE-2026-35163 — OctoPrint: XSS in Suppressed Command Notifications