Versions prior to 1.9.2 have a cross-site scripting (XSS) vulnerability that could be exploited when an authenticated user uploads a crafted image file for their avatar that gets rendered as a HTML file on the website.
id: CVE-2023-47115
info:
name: Label Studio - Cross-Site Scripting
author: isacaya
severity:
...