shouldiuse.io

Categories

VERDICT

Should I use CVAT.ai?

Turn raw images, videos, and 3D data into model-ready datasets with AI-assisted annotation, QA, analytics, APIs, and expert labeling services. - cvat.ai

Depends. Buy if your team labels images, video, or 3D data regularly and wants AI-assisted annotation with QA workflows and a free self-hosted option. Skip if you do one-off or non-vision labeling — simpler tools fit better.

Confidence

Medium. Based on 16 public sources: G2 reviews, Reddit threads, GitHub, vendor pricing/docs, and NVD/CVE databases. Pricing figures undisclosed by vendor; quotes truncated at source.

Ratings

  • Value for money
  • Ease of use
  • Feature depth
  • Support quality
  • Security posture

Pricing

Free

CVAT Community

ModelNot disclosed
Monthly feesNot disclosed
HardwareNot disclosed
Free tierYes
CVAT OnlineSubscription (annual plans available; prices undisclosed)
CVAT EnterpriseCustom quote
Labeling ServicesCustom quote

Best for

  • Computer vision teams labeling images/video/3D
  • ML teams needing QA and review workflows
  • Teams wanting open-source self-hosting
  • Orgs outsourcing labeling to experts

Not for

  • Solo users with one-off, small labeling jobs
  • Guess: NLP, audio, or tabular data labeling projects
  • Buyers with no DevOps help who want turnkey SaaS
  • Teams without an ML pipeline to feed

Gotchas - check before you buy

high

Steady CVE stream: patch self-hosted deployments quickly

medium

Cloud usage limits 'can be changed based on the company's needs' — negotiate before committing

medium

Self-hosted Community edition differs from paid Online; some features paywalled

medium

Enterprise private installs typically assisted by engineers — expect services costs

Pros and cons

Pros

  • Free, open-source core you can self-host
  • AI-assisted and automatic annotation modes speed labeling
  • Handles images, video, 3D, plus QA and analytics
  • Strong G2 reputation: 4.5/5 across 55 reviews
  • Managed expert labeling services available

Cons

  • Self-hosting demands DevOps effort
  • Community edition lacks paid Online features and limits
  • Multiple CVEs, including XSS and missing-authorization flaws
  • Pricing not transparent; usage limits negotiable, not published

Sources & method

Analyzed 9/24/2026 - 16 sources - Open-source with security policy, but 16 CVEs tracked since 2025, including XSS and missing-authorization flaws — patch self-hosted installs promptly.

official x6review x4security x3news x3
  • Stored XSS via annotation guide assets (GHSA-w6mx-95ff-72cv), Vendor-published GitHub security advisory for stored XSS.
  • CVE-2026-23516: CVAT XSS vulnerability, XSS flaw in canvas code, per SentinelOne vulnerability database.
  • CVE-2026-58373: Missing authorization, Improper authorization issue in cvat-ai per threat database.
  • CVE-2026-44369, Fixed in version 2.64.0 per NVD.

Key stats

  • Value for money: 4/5

    Rating

  • Free

    Starting price

  • 16

    Sources

  • Analyzed

  • Value for money: 4/5. Free open-source core; cloud pricing undisclosed
  • Ease of use: 3/5. Praised by pros; some seek video alternatives
  • Feature depth: 5/5. AI-assisted, video/3D, QA, analytics, APIs, services
  • Support quality: 3/5. Docs and academy strong; engineers for enterprise
  • Security posture: 2/5. 16 CVEs since 2025; XSS and auth flaws
  • 4.5/5 G2 rating 55 verified reviews
  • $9.6M Revenue 2024 ARR estimate
  • Yes Free tier Self-hosted Community edition
  • 2022 Spun out of Intel Now independent CVAT.ai

Pricing

CVAT Community

Free

  • Open-source, self-hosted
  • Core labeling features
  • You manage infrastructure

CVAT Online

Subscription (annual plans available; prices undisclosed)

  • Hosted, no infrastructure work
  • Usage limits, negotiable
  • Collaboration and QA tools

CVAT Enterprise

Not disclosed

  • Private installation
  • Engineer-assisted deployment
  • Security and compliance focus

Labeling Services

Not disclosed

  • Outsourced expert labeling
  • Feasibility sample first

Security

Open-source with security policy, but 16 CVEs tracked since 2025, including XSS and missing-authorization flaws — patch self-hosted installs promptly.

  • Stored XSS via annotation guide assets (GHSA-w6mx-95ff-72cv)Vendor-published GitHub security advisory for stored XSS.11
  • CVE-2026-23516: CVAT XSS vulnerabilityXSS flaw in canvas code, per SentinelOne vulnerability database.
  • CVE-2026-58373: Missing authorizationImproper authorization issue in cvat-ai per threat database.
  • CVE-2026-44369Fixed in version 2.64.0 per NVD.10

What users say

Users rate CVAT 4.5/5 on G2, favoring its AI and polygon tools for quality datasets, though some Reddit users hunt alternatives for video annotation.

“CVAT.ai solved two problems for me”
G2 review
“It would be great if it allows private datasets”
Reddit, r/computervision

Companies that use it

  • ProMetronics16
  • Jama
Full analysis

Based on 16 public sources: G2 reviews, Reddit threads, GitHub, vendor pricing/docs, and NVD/CVE databases. Pricing figures undisclosed by vendor; quotes truncated at source.

Serious vision-annotation platform, free if self-hosted. Overkill for small, one-off labeling jobs.

Methodology

Based on 16 public sources: G2 reviews, Reddit threads, GitHub, vendor pricing/docs, and NVD/CVE databases. Pricing figures undisclosed by vendor; quotes truncated at source.

Sources

  1. official
  2. review
  3. review
  4. CVAT on GitHubgithub.com
    official
  5. official
  6. official
  7. official
  8. review
  9. OpenCVE: CVAT CVEsapp.opencve.io
    security
  10. NVD CVE-2026-44369nvd.nist.gov
    security
  11. security
  12. news
  13. news
  14. news
  15. review
  16. official

Rate this review

Anonymous. You can change your vote.

Loading votes…

Comments

One queue. No nested comments. Give a display name first. Limit: 200 words per comment and 7 comments per day. You can edit or delete yours.

Save a name to write a comment.

0 / 200 words

No comments yet.