cvat-sdk is vulnerable to Cross-Site Scripting (XSS)
85
High Risk
The package fixed an XSS issue in annotation guide asset handling by adding server-side validation to ensure an uploaded asset’s declared Content-Type matches what the filename implies. Mismatches (e.g., uploading HTML while declaring an image type) are rejected, preventing the browser from interpreting the content as executable HTML.
You are affected if you are using a version that falls within the vulnerable range.
cvat-sdk is vulnerable to Cross-Site Scripting (XSS) in versions 2.5.0 - 2.66.0.
Upgrade the cvat-sdk library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant