CVE-2026-65986
Last modified
CVE-2026-65986 is a high-severity vulnerability rated 8.5/10 on the CVSS scale. CVAT is an open source interactive video and image annotation tool for computer vision. Versions 2.5.0 through 2.66.0 contain a XSS vulnerability that can be accessed through annotation guide assets. EPSS estimates a 0.24% chance of exploitation in the next 30 days.
Description
CVAT is an open source interactive video and image annotation tool for computer vision. Versions 2.5.0 through 2.66.0 contain a XSS vulnerability that can be accessed through annotation guide assets. When CVAT serves the files attached to an annotation guide, it labels them with a media type ( Content-Type ) that the attacker can influence, so instead of treating an uploaded file as plain data, the victim's browser can be told to treat it as an HTML page and run any JavaScript inside it. This issue has been fixed in version 2.67.0.
Metrics
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| cvat-ai | cvat | >= 2.5.0, < 2.67.0 |
References
Timeline
- Published
- Last Modified
- Status
- Awaiting Analysis
Frequently Asked Questions
What is CVE-2026-65986?
How severe is CVE-2026-65986?
How do I fix CVE-2026-65986?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-65979OpenEXR is the reference implementation and specification fo…6.7
- CVE-2026-6598A security vulnerability has been detected in langflow-ai la…4.3
- CVE-2026-65980Chartbrew is an open-source web application that can connect…7.9
- CVE-2026-65981Coturn is a free open source implementation of TURN and STUN…7.1
- CVE-2026-65984FUXA is a web-based Process Visualization (SCADA/HMI/Dashboa…7.5
- CVE-2026-65985FUXA is a web-based Process Visualization (SCADA/HMI/Dashboa…6
- CVE-2026-6599A vulnerability was detected in langflow-ai langflow up to 1…6.3
- CVE-2026-6600A flaw has been found in langflow-ai langflow up to 1.8.3. T…3.5
- CVE-2026-66000Frappe is a full-stack web application framework. Prior to 1…2.3
- CVE-2026-66001Frappe is a full-stack web application framework. Prior to 1…8.5
- CVE-2026-66002Frappe is a full-stack web application framework. Prior to 1…6.9
- CVE-2026-66003Frappe is a full-stack web application framework written in …7.1
Are you affected by CVE-2026-65986?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
