AVID-2026-R1042
Description
Server-Side Request Forgery Vulnerability in Computer Vision Annotation Tool (CVAT) (CVE-2022-31188)
Details
CVAT is an opensource interactive video and image annotation tool for computer vision. Versions prior to 2.0.0 were found to be subject to a Server-side request forgery (SSRF) vulnerability. Validation has been added to urls used in the affected code path in version 2.0.0. Users are advised to upgrade. There are no known workarounds for this issue.
Reason for inclusion in AVID: CVE-2022-31188 describes a server-side request forgery vulnerability in CVAT, an open-source data annotation tool widely used in AI/ML pipelines for labeling training data. This is a software vulnerability in a component (CVAT) that is part of the AI supply chain (data labeling, preprocessing, tooling, and deployment workflows). The vulnerability is security-focused (SSRF, potential data exposure) and the report provides explicit details and references, indicating sufficient evidence for curation.
References
- NVD entry
- https://github.com/cvat-ai/cvat/security/advisories/GHSA-7vpj-j5xv-29pr
- https://github.com/cvat-ai/cvat/commit/6fad1764efd922d99dbcda28c4ee72d071aa5a07
- http://packetstormsecurity.com/files/169814/CVAT-2.0-Server-Side-Request-Forgery.html
Affected or Relevant Artifacts
- Developer: cvat-ai
- Deployer: cvat-ai
- Artifact Details:
| Type | Name |
|---|---|
| System | cvat |
Impact
AVID Taxonomy Categorization
- Risk domains: Security
- SEP subcategories: S0100: Software Vulnerability
- Lifecycle stages: L06: Deployment
CVSS
| Version | 3.1 |
| Vector String | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:L |
| Base Score | 8.6 |
| Base Severity | 🔴 High |
| Attack Vector | NETWORK |
| Attack Complexity | 🟢 Low |
| Privileges Required | NONE |
| User Interaction | NONE |
| Scope | UNCHANGED |
| Confidentiality Impact | 🔴 High |
| Integrity Impact | 🟢 Low |
| Availability Impact | 🟢 Low |
CWE
| ID | Description |
|---|---|
| CWE-918 | CWE-918: Server-Side Request Forgery (SSRF) |
Other information
- Report Type: Advisory
- Credits:
- Date Reported: 2022-08-01
- Version: 0.3.3
- AVID Entry