CVE-2026-73219

CVAT is an open source interactive video and image annotation tool for computer vision. From 2.17.0 until 2.72.0, a user with write access to a CVAT job can submit a batch automatic annotation request to RequestViewSet.create with inconsistent task and job IDs, and because the task ID determines the single active request slot, block automatic annotation for another task whose ID is known. This issue is fixed in version 2.72.0.
CVSS

No CVSS.

Configurations

No configuration.

History

No history.

Information

Published : 2026-08-11 18:18

Updated : 2026-09-10 20:36


NVD link : CVE-2026-73219

Mitre link : CVE-2026-73219

CVE.ORG link : CVE-2026-73219


JSON object : View

Products Affected

No product.

CWE
CWE-1288

Improper Validation of Consistency within Input