CVE-2025-54573: CVAT vulnerable to email verification bypass by use of basic authentication
CVAT is an open source interactive video and image annotation tool for computer vision. In versions 1.1.0 through 2.41.0, email verification was not enforced when using Basic HTTP Authentication. As a result, users could create accounts using fake email addresses and use the product as verified users. Additionally, the missing email verification check leaves the system open to bot signups and further usage. CVAT 2.42.0 and later versions contain a fix for the issue. CVAT Enterprise customers have a workaround available; those customers may disable registration to prevent this issue.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2025-54573?
The severity of CVE-2025-54573 is considered to be high due to the potential for unauthorized account creation.
How do I fix CVE-2025-54573?
To fix CVE-2025-54573, upgrade to CVAT version 2.42.0 or later where email verification is enforced.
What types of accounts are affected by CVE-2025-54573?
CVE-2025-54573 affects accounts created with fake email addresses due to lack of email verification.
Which versions of CVAT are vulnerable to CVE-2025-54573?
CVAT versions 1.1.0 through 2.41.0 are vulnerable to CVE-2025-54573.
What are the implications of CVE-2025-54573 for users?
The implications of CVE-2025-54573 include potential misuse of resources by unauthorized users or spam accounts.