Label Studio是Heartex开源的一个开源数据标注工具。允许您使用简单明了的 UI 标记音频、文本、图像、视频和时间序列等数据类型,并导出为各种模型格式。 Label Studio 1.16.0之前版本存在跨站脚本漏洞,该漏洞源于允许通过GET请求注入任意HTML,并带有适当制作的查询参数。攻击者可以通过制作特殊格式的XML标签配置实现跨站脚本(XSS)攻击。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| HumanSignal | label-studio | < 1.16.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|---|---|---|
| 1 | Proof of Concept (POC) for the CVE-2025-25296 vulnerability affecting Label Studio versions prior to 1.16.0 | https://github.com/math-x-io/CVE-2025-25296-POC | POC Details |
| 2 | Label Studio prior to version 1.16.0 contains a cross-site scripting caused by rendering unsanitized user-provided HTML in the /projects/upload-example endpoint, letting attackers execute arbitrary JavaScript via crafted label_config in a GET request, exploit requires victims to visit malicious URL. | https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2025/CVE-2025-25296.yaml | POC Details |
No public POC found.
Login to generate AI POC| CVE-2025-25297 | 8.6 HIGH | Label Studio allows Server-Side Request Forgery in the S3 Storage Endpoint |
| CVE-2025-25295 | Label Studio has a Path Traversal Vulnerability via image Field |
No comments yet