CVE-2026-85211
- EPSS 0.24%
- Veröffentlicht 03.09.2026 14:12:22
- Zuletzt bearbeitet 10.09.2026 15:53:23
Label Studio fails to apply organization filters when resolving storage URIs for tasks and projects in proxy_api.py endpoints. Attackers can access other tenants' cloud storage objects by creating a separate organization and supplying arbitrary file ...
CVE-2026-85179
- EPSS 0.23%
- Veröffentlicht 03.09.2026 14:12:18
- Zuletzt bearbeitet 24.09.2026 20:43:32
Label Studio through 1.23.0 fails to validate webhook URLs, allowing authenticated users to dispatch requests to internal services including RFC 1918 addresses and cloud metadata endpoints. Attackers can create webhooks targeting private networks and...
CVE-2026-76073
- EPSS 0.28%
- Veröffentlicht 24.08.2026 17:55:39
- Zuletzt bearbeitet 24.09.2026 20:43:32
Label Studio does not scope the annotation detail endpoint to the requesting user's organization. AnnotationAPI in label_studio/tasks/api.py declares queryset = Annotation.objects.all() and provides no get_queryset override, so the default lookup ret...
CVE-2026-72560
- EPSS 0.2%
- Veröffentlicht 11.08.2026 11:12:38
- Zuletzt bearbeitet 03.09.2026 17:51:46
A server-side request forgery vulnerability in HumanSignal Label Studio through 1.24.0.dev0 exists because SSRF_PROTECTION_ENABLED is set to false by default. The import-from-URL endpoint fetches any caller-supplied URL including internal loopback ad...
CVE-2026-22033
- EPSS 0.25%
- Veröffentlicht 12.01.2026 17:47:34
- Zuletzt bearbeitet 27.01.2026 20:39:07
Label Studio is a multi-type data labeling and annotation tool. In 1.22.0 and earlier, a persistent stored cross-site scripting (XSS) vulnerability exists in the custom_hotkeys functionality of the application. An authenticated attacker (or one who c...
CVE-2025-47783
- EPSS 0.59%
- Veröffentlicht 14.05.2025 23:15:48
- Zuletzt bearbeitet 22.08.2025 20:24:03
Label Studio is a multi-type data labeling and annotation tool. A vulnerability in versions prior to 1.18.0 allows an attacker to inject a malicious script into the context of a web page, which can lead to data theft, session hijacking, unauthorized ...
CVE-2025-25296
- EPSS 1.9%
- Veröffentlicht 14.02.2025 20:15:36
- Zuletzt bearbeitet 25.08.2025 01:15:44
Label Studio is an open source data labeling tool. Prior to version 1.16.0, Label Studio's `/projects/upload-example` endpoint allows injection of arbitrary HTML through a `GET` request with an appropriately crafted `label_config` query parameter. By...
CVE-2025-25297
- EPSS 0.66%
- Veröffentlicht 14.02.2025 20:15:36
- Zuletzt bearbeitet 25.08.2025 01:17:33
Label Studio is an open source data labeling tool. Prior to version 1.16.0, Label Studio's S3 storage integration feature contains a Server-Side Request Forgery (SSRF) vulnerability in its endpoint configuration. When creating an S3 storage connectio...
CVE-2025-25295
- EPSS 0.75%
- Veröffentlicht 14.02.2025 17:15:20
- Zuletzt bearbeitet 15.04.2026 00:35:42
Label Studio is an open source data labeling tool. A path traversal vulnerability in Label Studio SDK versions prior to 1.0.10 allows unauthorized file access outside the intended directory structure. The flaw exists in the VOC, COCO and YOLO export ...
CVE-2024-26152
- EPSS 2.22%
- Veröffentlicht 22.02.2024 22:15:47
- Zuletzt bearbeitet 16.05.2025 14:18:25
### Summary On all Label Studio versions prior to 1.11.0, data imported via file upload feature is not properly sanitized prior to being rendered within a [`Choices`](https://labelstud.io/tags/choices) or [`Labels`](https://labelstud.io/tags/labels) ...