CVE-2025-64485: CVAT: Mounted share file overwrite via crafted request
CVAT is an open source interactive video and image annotation tool for computer vision. In versions 2.4.0 through 2.48.1, a malicious CVAT user with at least the User global role may create files in the root of the mounted file share, or overwrite existing files. If no file share is mounted, the user will be able to create files in the share directory of the import worker container, potentially filling up disk space. This issue is fixed in version 2.49.0.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-64485?
CVE-2025-64485 is considered a significant security vulnerability due to its potential for unauthorized file creation and overwriting by malicious users.
How do I fix CVE-2025-64485?
To fix CVE-2025-64485, upgrade CVAT to version 2.49.0 or later, where the vulnerability has been addressed.
What are the affected versions of CVE-2025-64485?
CVE-2025-64485 affects CVAT versions from 2.4.0 to 2.48.1.
What kind of users are affected by CVE-2025-64485?
Users with at least the User global role in CVAT can exploit CVE-2025-64485 to create or overwrite files.
Is CVE-2025-64485 critical for security?
Yes, CVE-2025-64485 poses a critical risk as it allows malicious users to manipulate files on the server.