Intel

AIKIDO-2026-10001

cvat-sdk is vulnerable to Path Traversal

Path TraversalCVE-2025-68430 Published Jan 6, 2026

53

Medium Risk

This Affects:

PYTHONcvat-sdk
2.8.1 - 2.52.0
Fixed in 2.53.0
Are you affected? Scan for Free

TL;DR

Affected versions of this package are vulnerable to Path Traversal. An authenticated attacker with an account on a CVAT instance can list the contents of any file system directory accessible to the CVAT server, exposing the names of files and subdirectories. File contents themselves are not disclosed.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

cvat-sdk is vulnerable to Path Traversal in versions 2.8.1 - 2.52.0.

How to fix this

Upgrade the cvat-sdk library to the patch version.