CVE-2025-23045 - CVE House
Back to Database
Status published High CVE-2025-23045

CVAT allows remote code execution via tracker Nuclio functions

Vulnerability Description

Computer Vision Annotation Tool (CVAT) is an interactive video and image annotation tool for computer vision. An attacker with an account on an affected CVAT instance is able to run arbitrary code in the context of the Nuclio function container. This vulnerability affects CVAT deployments that run any of the serverless functions of type tracker from the CVAT Git repository, namely TransT and SiamMask. Deployments with custom functions of type tracker may also be affected, depending on how they handle state serialization. If a function uses an unsafe serialization library such as pickle or jsonpickle, it's likely to be vulnerable. Upgrade to CVAT 2.26.0 or later. If you are unable to upgrade, shut down any instances of the TransT or SiamMask functions you're running.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-23045

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

Affected Software

cvat
Vulnerable Versions:
>= 1.1.0, < 2.26.0

Timeline

Official Publish: January 28th, 2025
Last Modified: January 28th, 2025
Added to House: July 22nd, 2026

CVSS Vectors

Weaknesses (CWE)