CVE-2026-23516 | cvat up to 2.54.x cross site scripting (GHSA-3m7p-wx65-c7mp / EUVD-2026-3774)
A vulnerability marked as critical has been reported in cvat up to 2.54.x. This impacts an unknown function. This manipulation causes improper neutralization of script in attributes in a web page.
This vulnerability is handled as CVE-2026-23516. The attack can be initiated remotely. There is not any exploit available.
It is suggested to upgrade the affected component.