Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

label-studio — Vulnerabilities & Security Advisories 14

All 14 CVE vulnerabilities found in label-studio, with AI-generated Chinese analysis, references, and POCs.

This page aggregates security vulnerabilities for the label-studio product. It collects recorded defects across multiple weakness classes, covering the full historical timeline of known issues. Visitors can use this resource to track vendor advisories, understand specific weakness categories, and review the complete vulnerability history for this software.

Vendor: HumanSignal

CVE ID Title CVSS Severity Published
CVE-2026-85211 Label Studio through 1.23.0 Cross-Organization Storage URI Resolution CWE-639 7.7 High 2026-09-03
CVE-2026-85179 Label Studio through 1.23.0 SSRF via Unvalidated Webhook URL CWE-918 8.5 High 2026-09-03
CVE-2026-76073 Label Studio through 1.23.0 Cross-Organization Annotation Access via Unscoped AnnotationAPI Queryset CWE-639 8.8 High 2026-08-24
CVE-2026-22033 Label Studio vulnerable to full account takeover by chaining Stored XSS + IDOR in User Profile via custom_hotkeys field CWE-79 5.4AI Medium AI 2026-01-12
CVE-2025-47783 label-studio vulnerable to Cross-Site Scripting (Reflected) via the label_config parameter. CWE-79 8.2AI High AI 2025-05-14
CVE-2025-25297 Label Studio allows Server-Side Request Forgery in the S3 Storage Endpoint CWE-918 8.6 High 2025-02-14
CVE-2025-25296 Label Studio allows Cross-Site Scripting (XSS) via GET request to `/projects/upload-example` endpoint CWE-79 6.1 Medium 2025-02-14
CVE-2025-25295 Label Studio has a Path Traversal Vulnerability via image Field CWE-22 7.5 - 2025-02-14
CVE-2024-26152 Label Studio vulnerable to Cross-site Scripting if `<Choices>` or `<Labels>` are used in labeling config CWE-79 4.7 Medium 2024-02-22
CVE-2023-47116 Label Studio SSRF on Import Bypassing `SSRF_PROTECTION_ENABLED` Protections CWE-918 5.3 Medium 2024-01-31
CVE-2024-23633 Label Studio XSS Vulnerability on Data Import CWE-79 4.7 Medium 2024-01-23
CVE-2023-47115 Label Studio XSS Vulnerability on Avatar Upload CWE-79 7.1 High 2024-01-23
CVE-2023-47117 Object Relational Mapper Leak Vulnerability in Filtering Task in Label Studio CWE-200 7.5 High 2023-11-13
CVE-2023-43791 Label Studio has Hardcoded Django `SECRET_KEY` that can be Abused to Forge Session Tokens CWE-200 9.8 Critical 2023-11-09

All 14 known CVE vulnerabilities affecting label-studio with full Chinese analysis, references, and POCs where available.