Intel

AIKIDO-2025-10524

cvat-sdk is vulnerable to Improper Authentication

Improper AuthenticationCVE-2025-54573 Published Aug 3, 2025

43

Medium Risk

This Affects:

PYTHONcvat-sdk
1.1.0 - 2.41.0
Fixed in 2.42.0
Are you affected? Scan for Free

TL;DR

Email verification was not enforced when using Basic HTTP Authentication. As a result, users could create accounts using fake email addresses and use the product as verified users. Additionally, the missing email verification check leaves the system open to bot signups and further usage.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

cvat-sdk is vulnerable to Improper Authentication in versions 1.1.0 - 2.41.0.

How to fix this

Upgrade the cvat-sdk library to the patch version.