What is CVE-2026-65986?
An XSS vulnerability has been identified in the open-source CVAT annotation tool (versions 2.5.0 through 2.66.0) that can be triggered via annotation guide assets. An attacker could potentially exploit this to hijack user sessions. Users are strongly advised to update to the latest version immediately and avoid loading annotation guides from untrusted sources.
Azərbaycanca: CVAT açıq mənbəli annotasiya alətində (versiya 2.5.0 - 2.66.0) annotasiya təlimatı faylları vasitəsilə istifadə edilə bilən XSS zəifliyi aşkarlanıb. Bu, təcavüzkara istifadəçi sessiyalarını ələ keçirməyə imkan verə bilər. İstifadəçilərə dərhal ən son versiyaya yeniləmə və etibarsız mənbələrdən annotasiya təlimatlarını yükləməmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-79
FAQ2
Which versions of the CVAT tool are affected by CVE-2026-65986?
The vulnerability affects CVAT annotation tool versions 2.5.0 through 2.66.0.
How can CVE-2026-65986 impact user sessions?
An attacker can hijack user sessions by exploiting an XSS vulnerability triggered via annotation guide assets.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.