CVE-2025-68430: CVAT vulnerable to directory traversal via mounted share listing
CVAT is an open source interactive video and image annotation tool for computer vision. In versions 2.8.1 through 2.52.0, an attacker with an account on a CVAT instance is able to retrieve the contents of any file system directory accessible to the CVAT server. The exposed information is names of contained files and subdirectories. The contents of files are not accessible. Version 2.53.0 contains a patch. No known workarounds are available.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2025-68430?
CVE-2025-68430 is considered a high severity vulnerability due to its potential for unauthorized access to sensitive file system directories.
How do I fix CVE-2025-68430?
To fix CVE-2025-68430, upgrade your CVAT instance to version 2.8.1 or later, ensuring you are not on any affected versions up to 2.52.0.
Who is affected by CVE-2025-68430?
Any user with an account on a CVAT instance running versions 2.8.1 through 2.52.0 is vulnerable to CVE-2025-68430.
What can an attacker do with CVE-2025-68430?
An attacker exploiting CVE-2025-68430 can retrieve the contents of any file system directory that is accessible to the CVAT server.
When was CVE-2025-68430 disclosed?
CVE-2025-68430 was disclosed in the context of CVAT versions affected between 2.8.1 and 2.52.0.