← Vulnerability feed

Vulnerability record · CVE-2022-31188 · published 1 August 2022

CVE-2022-31188: CVAT annotation tool vulnerable to unauthenticated SSRF

Cvat · Computer Vision Annotation Tool

CVAT versions before 2.0.0 do not validate URLs used in an affected code path, allowing server-side request forgery. An attacker can make the CVAT server issue requests to arbitrary URLs, which matters because the server often sits inside a trusted network with access to internal services.

9.8 CVSS 3.1 Critical EPSS 49% · top 1.2% CWE-918 · Server-side request forgery (SSRF)
9.8CVSS 3.1 base score
49%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
6References, 2 tagged exploit
17 Jun 2026Last modified by NVD

Description

CVAT is an opensource interactive video and image annotation tool for computer vision. Versions prior to 2.0.0 were found to be subject to a Server-side request forgery (SSRF) vulnerability. Validation has been added to urls used in the affected code path in version 2.0.0. Users are advised to upgrade. There are no known workarounds for this issue.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 20 September 2026. Confidence: high.

critical priorityCVSS 9.8 with network reachability, no authentication, no user interaction, and a public exploit reference make this a high-urgency fix despite no KEV listing.

What it is

CVAT versions before 2.0.0 do not validate URLs used in an affected code path, allowing server-side request forgery. An attacker can make the CVAT server issue requests to arbitrary URLs, which matters because the server often sits inside a trusted network with access to internal services.

Impact

An attacker gains the ability to send requests from the CVAT server to internal or external systems, potentially reaching internal services, cloud metadata endpoints, or other resources not otherwise exposed. The CVSS vector rates confidentiality, integrity and availability impact as high.

Attack surface

The flaw is reachable over the network with no authentication and no user interaction required, per the CVSS vector AV:N/AC:L/PR:N/UI:N. The description does not name the exact endpoint or parameter, so the precise request path is not specified in the record.

Exploitation

CISA KEV does not list this CVE, but EPSS is high at roughly 0.486 (98.8th percentile), and a public exploit reference exists on Packet Storm. No ransomware usage is documented.

What to do

  • Upgrade CVAT to version 2.0.0 or later, which adds URL validation in the affected code path.
  • If immediate upgrade is not possible, restrict outbound network access from the CVAT server to only required destinations.
  • Block access from CVAT hosts to cloud instance metadata endpoints and internal management interfaces.
  • Place CVAT behind authentication and network controls so it is not reachable by untrusted clients.
  • Monitor for vendor guidance, since the record states there are no known workarounds.

Detection

  • Review CVAT server logs for outbound requests to unusual or internal-only hosts and IP addresses.
  • Alert on requests from CVAT hosts to link-local or metadata addresses such as 169.254.169.254.
  • Baseline normal outbound destinations for the CVAT server and flag deviations.
  • Correlate CVAT process activity with network connections to non-approved internal services.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2022-31188 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.0CVE-2021-45046Apache Log4j 2.15.0 Incomplete Fix Allows JNDI Lookup InjectionThe fix for CVE-2021-44228 in Apache Log4j 2.15.0 was incomplete in certain non-default configurations. When a non-default Pattern Layout uses a Cont…KEVEPSS 100%analysed8.7CVE-2025-23045Cvat computer vision annotation tool deserialization of untrusted data vulnerabilityComputer Vision Annotation Tool (CVAT) is an interactive video and image annotation tool for computer vision. An attacker with an account on an affec…EPSS 0.50%8.6CVE-2026-23516Cvat computer vision annotation tool cross-site scripting vulnerabilityCVAT is an open source interactive video and image annotation tool for computer vision. In versions 2.2.0 through 2.54.0, an attacker is able to exec…EPSS 0.17%8.5CVE-2026-23526Cvat computer vision annotation tool vulnerabilityCVAT is an open source interactive video and image annotation tool for computer vision. In versions 1.0.0 through 2.54.0, users that have the staff s…EPSS 0.29%8.5CVE-2024-37164Cvat computer vision annotation tool server-side request forgery (ssrf) vulnerabilityComputer Vision Annotation Tool (CVAT) is an interactive video and image annotation tool for computer vision. CVAT allows users to supply custom endp…EPSS 0.35%7.1CVE-2024-37306Cvat computer vision annotation tool cross-site request forgery vulnerabilityComputer Vision Annotation Tool (CVAT) is an interactive video and image annotation tool for computer vision. Starting in version 2.2.0 and prior to …EPSS 0.21%6.5CVE-2025-54573Cvat computer vision annotation tool improper authentication vulnerabilityCVAT is an open source interactive video and image annotation tool for computer vision. In versions 1.1.0 through 2.41.0, email verification was not …EPSS 0.27%6.4CVE-2024-45393Cvat computer vision annotation tool missing authorization vulnerabilityComputer Vision Annotation Tool (CVAT) is an interactive video and image annotation tool for computer vision. An attacker with a CVAT account can acc…EPSS 0.24%

Source: NIST National Vulnerability Database (record CVE-2022-31188), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.