Intel

AIKIDO-2026-10001

cvat-sdk is vulnerable to Path Traversal

Path TraversalCVE-2025-68430 Published Jan 6, 2026

53

Medium Risk

This Affects:

PYTHONcvat-sdk
2.8.1 - 2.52.0
Fixed in 2.53.0
Are you affected? Scan for Free

TL;DR

Affected versions of this package are vulnerable to Path Traversal. An authenticated attacker with an account on a CVAT instance can list the contents of any file system directory accessible to the CVAT server, exposing the names of files and subdirectories. File contents themselves are not disclosed.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

cvat-sdk is vulnerable to Path Traversal in versions 2.8.1 - 2.52.0.

How to fix this

Upgrade the cvat-sdk library to the patch version.

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform