label-studio
Label Studio annotation tool
Activity
- Latest release
- 6mo ago
- Total releases
- 96
- Cadence
- ~27 days
- Last 12 months
- 2
Reach
- Stars
- —
Details
- License
- Apache-2.0
- First release
- Jan 10, 2020
| Version | Released | |
|---|---|---|
1.23.0
minor
| ||
1.22.0
minor
1 CVE
CVE-2026-22033
PYSEC-2026-1502
GHSA-2mq9-hm29-8qch
Jul 07, 2026
Label Studio is vulnerable to full account takeover by chaining Stored XSS + IDOR in User Profile via custom_hotkeys field
Critical
Network
Low
Low
None
PrologueThese vulnerabilities have been found and chained by DCODX-AI. Validation of the exploit chain has been confirmed manually. SummaryA persistent stored cross-site scripting (XSS) vulnerability exists in the custom_hotkeys functionality of the application. An authenticated attacker (or one who can trick a user/administrator into updating their custom_hotkeys) can inject JavaScript code that executes in other users’ browsers when those users load any page using the DetailsWithin
Here, user.custom_hotkeys is run through json_dumps_ensure_ascii (in In
The serializer allows
When another user loads a page using templates/base.html (for example PoC
Example request
Example response
ImpactExploitation impact:
Who is impacted:
Affected versions
0.4.1
0.4.2
0.4.3
0.4.4
0.4.4.post1
0.4.4.post2
0.4.5
0.4.6
0.4.6.post1
0.4.6.post2
0.4.7
0.4.8
+ 83 more Show less
0.5.0
0.5.1
0.6.0
0.6.1
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.4.post0
0.7.4.post1
0.7.5.post1
0.7.5.post2
0.8.0
0.8.0.post0
0.8.1
0.8.1.post0
0.8.2
0.8.2.post0
0.9.0
0.9.0.post2
0.9.0.post3
0.9.0.post4
0.9.0.post5
0.9.1
0.9.1.post0
0.9.1.post1
0.9.1.post2
1.0.0
1.0.0.post0
1.0.0.post1
1.0.0.post2
1.0.0.post3
1.0.1
1.0.2
1.0.2.post0
1.1.0
1.1.0rc0
1.1.1
1.10.0
1.10.0.post0
1.10.1
1.11.0
1.12.0
1.12.0.post0
1.12.1
1.13.0
1.13.1
1.14.0
1.14.0.post0
1.15.0
1.16.0
1.17.0
1.18.0
1.19.0
1.2
1.20.0
1.21.0
1.22.0
1.3
1.3.post0
1.3.post1
1.4
1.4.1
1.4.1.post0
1.4.1.post1
1.5.0
1.5.0.post0
1.6.0
1.7.0
1.7.1
1.7.2
1.7.3
1.8.0
1.8.1
1.8.2
1.8.2.post0
1.8.2.post1
1.9.0
1.9.1
1.9.1.post0
1.9.2
1.9.2.post0
References
Updated Jul 07, 2026 · Source: OSV.dev | ||
1.21.0
minor
1 CVE
CVE-2026-22033
PYSEC-2026-1502
GHSA-2mq9-hm29-8qch
Jul 07, 2026
Label Studio is vulnerable to full account takeover by chaining Stored XSS + IDOR in User Profile via custom_hotkeys field
Critical
Network
Low
Low
None
PrologueThese vulnerabilities have been found and chained by DCODX-AI. Validation of the exploit chain has been confirmed manually. SummaryA persistent stored cross-site scripting (XSS) vulnerability exists in the custom_hotkeys functionality of the application. An authenticated attacker (or one who can trick a user/administrator into updating their custom_hotkeys) can inject JavaScript code that executes in other users’ browsers when those users load any page using the DetailsWithin
Here, user.custom_hotkeys is run through json_dumps_ensure_ascii (in In
The serializer allows
When another user loads a page using templates/base.html (for example PoC
Example request
Example response
ImpactExploitation impact:
Who is impacted:
Affected versions
0.4.1
0.4.2
0.4.3
0.4.4
0.4.4.post1
0.4.4.post2
0.4.5
0.4.6
0.4.6.post1
0.4.6.post2
0.4.7
0.4.8
+ 83 more Show less
0.5.0
0.5.1
0.6.0
0.6.1
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.4.post0
0.7.4.post1
0.7.5.post1
0.7.5.post2
0.8.0
0.8.0.post0
0.8.1
0.8.1.post0
0.8.2
0.8.2.post0
0.9.0
0.9.0.post2
0.9.0.post3
0.9.0.post4
0.9.0.post5
0.9.1
0.9.1.post0
0.9.1.post1
0.9.1.post2
1.0.0
1.0.0.post0
1.0.0.post1
1.0.0.post2
1.0.0.post3
1.0.1
1.0.2
1.0.2.post0
1.1.0
1.1.0rc0
1.1.1
1.10.0
1.10.0.post0
1.10.1
1.11.0
1.12.0
1.12.0.post0
1.12.1
1.13.0
1.13.1
1.14.0
1.14.0.post0
1.15.0
1.16.0
1.17.0
1.18.0
1.19.0
1.2
1.20.0
1.21.0
1.22.0
1.3
1.3.post0
1.3.post1
1.4
1.4.1
1.4.1.post0
1.4.1.post1
1.5.0
1.5.0.post0
1.6.0
1.7.0
1.7.1
1.7.2
1.7.3
1.8.0
1.8.1
1.8.2
1.8.2.post0
1.8.2.post1
1.9.0
1.9.1
1.9.1.post0
1.9.2
1.9.2.post0
References
Updated Jul 07, 2026 · Source: OSV.dev | ||
1.20.0
minor
1 CVE
CVE-2026-22033
PYSEC-2026-1502
GHSA-2mq9-hm29-8qch
Jul 07, 2026
Label Studio is vulnerable to full account takeover by chaining Stored XSS + IDOR in User Profile via custom_hotkeys field
Critical
Network
Low
Low
None
PrologueThese vulnerabilities have been found and chained by DCODX-AI. Validation of the exploit chain has been confirmed manually. SummaryA persistent stored cross-site scripting (XSS) vulnerability exists in the custom_hotkeys functionality of the application. An authenticated attacker (or one who can trick a user/administrator into updating their custom_hotkeys) can inject JavaScript code that executes in other users’ browsers when those users load any page using the DetailsWithin
Here, user.custom_hotkeys is run through json_dumps_ensure_ascii (in In
The serializer allows
When another user loads a page using templates/base.html (for example PoC
Example request
Example response
ImpactExploitation impact:
Who is impacted:
Affected versions
0.4.1
0.4.2
0.4.3
0.4.4
0.4.4.post1
0.4.4.post2
0.4.5
0.4.6
0.4.6.post1
0.4.6.post2
0.4.7
0.4.8
+ 83 more Show less
0.5.0
0.5.1
0.6.0
0.6.1
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.4.post0
0.7.4.post1
0.7.5.post1
0.7.5.post2
0.8.0
0.8.0.post0
0.8.1
0.8.1.post0
0.8.2
0.8.2.post0
0.9.0
0.9.0.post2
0.9.0.post3
0.9.0.post4
0.9.0.post5
0.9.1
0.9.1.post0
0.9.1.post1
0.9.1.post2
1.0.0
1.0.0.post0
1.0.0.post1
1.0.0.post2
1.0.0.post3
1.0.1
1.0.2
1.0.2.post0
1.1.0
1.1.0rc0
1.1.1
1.10.0
1.10.0.post0
1.10.1
1.11.0
1.12.0
1.12.0.post0
1.12.1
1.13.0
1.13.1
1.14.0
1.14.0.post0
1.15.0
1.16.0
1.17.0
1.18.0
1.19.0
1.2
1.20.0
1.21.0
1.22.0
1.3
1.3.post0
1.3.post1
1.4
1.4.1
1.4.1.post0
1.4.1.post1
1.5.0
1.5.0.post0
1.6.0
1.7.0
1.7.1
1.7.2
1.7.3
1.8.0
1.8.1
1.8.2
1.8.2.post0
1.8.2.post1
1.9.0
1.9.1
1.9.1.post0
1.9.2
1.9.2.post0
References
Updated Jul 07, 2026 · Source: OSV.dev | ||
1.19.0
minor
1 CVE
CVE-2026-22033
PYSEC-2026-1502
GHSA-2mq9-hm29-8qch
Jul 07, 2026
Label Studio is vulnerable to full account takeover by chaining Stored XSS + IDOR in User Profile via custom_hotkeys field
Critical
Network
Low
Low
None
PrologueThese vulnerabilities have been found and chained by DCODX-AI. Validation of the exploit chain has been confirmed manually. SummaryA persistent stored cross-site scripting (XSS) vulnerability exists in the custom_hotkeys functionality of the application. An authenticated attacker (or one who can trick a user/administrator into updating their custom_hotkeys) can inject JavaScript code that executes in other users’ browsers when those users load any page using the DetailsWithin
Here, user.custom_hotkeys is run through json_dumps_ensure_ascii (in In
The serializer allows
When another user loads a page using templates/base.html (for example PoC
Example request
Example response
ImpactExploitation impact:
Who is impacted:
Affected versions
0.4.1
0.4.2
0.4.3
0.4.4
0.4.4.post1
0.4.4.post2
0.4.5
0.4.6
0.4.6.post1
0.4.6.post2
0.4.7
0.4.8
+ 83 more Show less
0.5.0
0.5.1
0.6.0
0.6.1
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.4.post0
0.7.4.post1
0.7.5.post1
0.7.5.post2
0.8.0
0.8.0.post0
0.8.1
0.8.1.post0
0.8.2
0.8.2.post0
0.9.0
0.9.0.post2
0.9.0.post3
0.9.0.post4
0.9.0.post5
0.9.1
0.9.1.post0
0.9.1.post1
0.9.1.post2
1.0.0
1.0.0.post0
1.0.0.post1
1.0.0.post2
1.0.0.post3
1.0.1
1.0.2
1.0.2.post0
1.1.0
1.1.0rc0
1.1.1
1.10.0
1.10.0.post0
1.10.1
1.11.0
1.12.0
1.12.0.post0
1.12.1
1.13.0
1.13.1
1.14.0
1.14.0.post0
1.15.0
1.16.0
1.17.0
1.18.0
1.19.0
1.2
1.20.0
1.21.0
1.22.0
1.3
1.3.post0
1.3.post1
1.4
1.4.1
1.4.1.post0
1.4.1.post1
1.5.0
1.5.0.post0
1.6.0
1.7.0
1.7.1
1.7.2
1.7.3
1.8.0
1.8.1
1.8.2
1.8.2.post0
1.8.2.post1
1.9.0
1.9.1
1.9.1.post0
1.9.2
1.9.2.post0
References
Updated Jul 07, 2026 · Source: OSV.dev | ||
1.18.0
minor
1 CVE
CVE-2026-22033
PYSEC-2026-1502
GHSA-2mq9-hm29-8qch
Jul 07, 2026
Label Studio is vulnerable to full account takeover by chaining Stored XSS + IDOR in User Profile via custom_hotkeys field
Critical
Network
Low
Low
None
PrologueThese vulnerabilities have been found and chained by DCODX-AI. Validation of the exploit chain has been confirmed manually. SummaryA persistent stored cross-site scripting (XSS) vulnerability exists in the custom_hotkeys functionality of the application. An authenticated attacker (or one who can trick a user/administrator into updating their custom_hotkeys) can inject JavaScript code that executes in other users’ browsers when those users load any page using the DetailsWithin
Here, user.custom_hotkeys is run through json_dumps_ensure_ascii (in In
The serializer allows
When another user loads a page using templates/base.html (for example PoC
Example request
Example response
ImpactExploitation impact:
Who is impacted:
Affected versions
0.4.1
0.4.2
0.4.3
0.4.4
0.4.4.post1
0.4.4.post2
0.4.5
0.4.6
0.4.6.post1
0.4.6.post2
0.4.7
0.4.8
+ 83 more Show less
0.5.0
0.5.1
0.6.0
0.6.1
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.4.post0
0.7.4.post1
0.7.5.post1
0.7.5.post2
0.8.0
0.8.0.post0
0.8.1
0.8.1.post0
0.8.2
0.8.2.post0
0.9.0
0.9.0.post2
0.9.0.post3
0.9.0.post4
0.9.0.post5
0.9.1
0.9.1.post0
0.9.1.post1
0.9.1.post2
1.0.0
1.0.0.post0
1.0.0.post1
1.0.0.post2
1.0.0.post3
1.0.1
1.0.2
1.0.2.post0
1.1.0
1.1.0rc0
1.1.1
1.10.0
1.10.0.post0
1.10.1
1.11.0
1.12.0
1.12.0.post0
1.12.1
1.13.0
1.13.1
1.14.0
1.14.0.post0
1.15.0
1.16.0
1.17.0
1.18.0
1.19.0
1.2
1.20.0
1.21.0
1.22.0
1.3
1.3.post0
1.3.post1
1.4
1.4.1
1.4.1.post0
1.4.1.post1
1.5.0
1.5.0.post0
1.6.0
1.7.0
1.7.1
1.7.2
1.7.3
1.8.0
1.8.1
1.8.2
1.8.2.post0
1.8.2.post1
1.9.0
1.9.1
1.9.1.post0
1.9.2
1.9.2.post0
References
Updated Jul 07, 2026 · Source: OSV.dev | ||
1.17.0
minor
2 CVEs
CVE-2026-22033
PYSEC-2026-1502
GHSA-2mq9-hm29-8qch
Jul 07, 2026
Label Studio is vulnerable to full account takeover by chaining Stored XSS + IDOR in User Profile via custom_hotkeys field
Critical
Network
Low
Low
None
PrologueThese vulnerabilities have been found and chained by DCODX-AI. Validation of the exploit chain has been confirmed manually. SummaryA persistent stored cross-site scripting (XSS) vulnerability exists in the custom_hotkeys functionality of the application. An authenticated attacker (or one who can trick a user/administrator into updating their custom_hotkeys) can inject JavaScript code that executes in other users’ browsers when those users load any page using the DetailsWithin
Here, user.custom_hotkeys is run through json_dumps_ensure_ascii (in In
The serializer allows
When another user loads a page using templates/base.html (for example PoC
Example request
Example response
ImpactExploitation impact:
Who is impacted:
Affected versions
0.4.1
0.4.2
0.4.3
0.4.4
0.4.4.post1
0.4.4.post2
0.4.5
0.4.6
0.4.6.post1
0.4.6.post2
0.4.7
0.4.8
+ 83 more Show less
0.5.0
0.5.1
0.6.0
0.6.1
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.4.post0
0.7.4.post1
0.7.5.post1
0.7.5.post2
0.8.0
0.8.0.post0
0.8.1
0.8.1.post0
0.8.2
0.8.2.post0
0.9.0
0.9.0.post2
0.9.0.post3
0.9.0.post4
0.9.0.post5
0.9.1
0.9.1.post0
0.9.1.post1
0.9.1.post2
1.0.0
1.0.0.post0
1.0.0.post1
1.0.0.post2
1.0.0.post3
1.0.1
1.0.2
1.0.2.post0
1.1.0
1.1.0rc0
1.1.1
1.10.0
1.10.0.post0
1.10.1
1.11.0
1.12.0
1.12.0.post0
1.12.1
1.13.0
1.13.1
1.14.0
1.14.0.post0
1.15.0
1.16.0
1.17.0
1.18.0
1.19.0
1.2
1.20.0
1.21.0
1.22.0
1.3
1.3.post0
1.3.post1
1.4
1.4.1
1.4.1.post0
1.4.1.post1
1.5.0
1.5.0.post0
1.6.0
1.7.0
1.7.1
1.7.2
1.7.3
1.8.0
1.8.1
1.8.2
1.8.2.post0
1.8.2.post1
1.9.0
1.9.1
1.9.1.post0
1.9.2
1.9.2.post0
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-47783
GHSA-8jhr-wpcm-hh4h
PYSEC-2025-124
May 15, 2025
label-studio vulnerable to Cross-Site Scripting (Reflected) via the label_config parameter.
High
Network
Low
None
SummaryThe vulnerability allows an attacker to inject a malicious script into the context of a web page, which can lead to data theft, unauthorized actions on behalf of the user, and other attacks. DetailsThe vulnerability is reproducible when sending a properly formatted request to the
The vulnerability is specifically located in line 57, where HttpResponse is used.
PoCSend the following request after changing the
Or you can create a vulnerable HTML page by changing
Impact
Affected versions
0.4.1
0.4.2
0.4.3
0.4.4
0.4.4.post1
0.4.4.post2
0.4.5
0.4.6
0.4.6.post1
0.4.6.post2
0.4.7
0.4.8
+ 78 more Show less
0.5.0
0.5.1
0.6.0
0.6.1
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.4.post0
0.7.4.post1
0.7.5.post1
0.7.5.post2
0.8.0
0.8.0.post0
0.8.1
0.8.1.post0
0.8.2
0.8.2.post0
0.9.0
0.9.0.post2
0.9.0.post3
0.9.0.post4
0.9.0.post5
0.9.1
0.9.1.post0
0.9.1.post1
0.9.1.post2
1.0.0
1.0.0.post0
1.0.0.post1
1.0.0.post2
1.0.0.post3
1.0.1
1.0.2
1.0.2.post0
1.1.0
1.1.0rc0
1.1.1
1.10.0
1.10.0.post0
1.10.1
1.11.0
1.12.0
1.12.0.post0
1.12.1
1.13.0
1.13.1
1.14.0
1.14.0.post0
1.15.0
1.16.0
1.17.0
1.2
1.3
1.3.post0
1.3.post1
1.4
1.4.1
1.4.1.post0
1.4.1.post1
1.5.0
1.5.0.post0
1.6.0
1.7.0
1.7.1
1.7.2
1.7.3
1.8.0
1.8.1
1.8.2
1.8.2.post0
1.8.2.post1
1.9.0
1.9.1
1.9.1.post0
1.9.2
1.9.2.post0
Fixed in
1.18.0
References
Updated Jun 06, 2026 · Source: OSV.dev | ||
1.16.0
minor
2 CVEs
CVE-2026-22033
PYSEC-2026-1502
GHSA-2mq9-hm29-8qch
Jul 07, 2026
Label Studio is vulnerable to full account takeover by chaining Stored XSS + IDOR in User Profile via custom_hotkeys field
Critical
Network
Low
Low
None
PrologueThese vulnerabilities have been found and chained by DCODX-AI. Validation of the exploit chain has been confirmed manually. SummaryA persistent stored cross-site scripting (XSS) vulnerability exists in the custom_hotkeys functionality of the application. An authenticated attacker (or one who can trick a user/administrator into updating their custom_hotkeys) can inject JavaScript code that executes in other users’ browsers when those users load any page using the DetailsWithin
Here, user.custom_hotkeys is run through json_dumps_ensure_ascii (in In
The serializer allows
When another user loads a page using templates/base.html (for example PoC
Example request
Example response
ImpactExploitation impact:
Who is impacted:
Affected versions
0.4.1
0.4.2
0.4.3
0.4.4
0.4.4.post1
0.4.4.post2
0.4.5
0.4.6
0.4.6.post1
0.4.6.post2
0.4.7
0.4.8
+ 83 more Show less
0.5.0
0.5.1
0.6.0
0.6.1
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.4.post0
0.7.4.post1
0.7.5.post1
0.7.5.post2
0.8.0
0.8.0.post0
0.8.1
0.8.1.post0
0.8.2
0.8.2.post0
0.9.0
0.9.0.post2
0.9.0.post3
0.9.0.post4
0.9.0.post5
0.9.1
0.9.1.post0
0.9.1.post1
0.9.1.post2
1.0.0
1.0.0.post0
1.0.0.post1
1.0.0.post2
1.0.0.post3
1.0.1
1.0.2
1.0.2.post0
1.1.0
1.1.0rc0
1.1.1
1.10.0
1.10.0.post0
1.10.1
1.11.0
1.12.0
1.12.0.post0
1.12.1
1.13.0
1.13.1
1.14.0
1.14.0.post0
1.15.0
1.16.0
1.17.0
1.18.0
1.19.0
1.2
1.20.0
1.21.0
1.22.0
1.3
1.3.post0
1.3.post1
1.4
1.4.1
1.4.1.post0
1.4.1.post1
1.5.0
1.5.0.post0
1.6.0
1.7.0
1.7.1
1.7.2
1.7.3
1.8.0
1.8.1
1.8.2
1.8.2.post0
1.8.2.post1
1.9.0
1.9.1
1.9.1.post0
1.9.2
1.9.2.post0
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-47783
GHSA-8jhr-wpcm-hh4h
PYSEC-2025-124
May 15, 2025
label-studio vulnerable to Cross-Site Scripting (Reflected) via the label_config parameter.
High
Network
Low
None
SummaryThe vulnerability allows an attacker to inject a malicious script into the context of a web page, which can lead to data theft, unauthorized actions on behalf of the user, and other attacks. DetailsThe vulnerability is reproducible when sending a properly formatted request to the
The vulnerability is specifically located in line 57, where HttpResponse is used.
PoCSend the following request after changing the
Or you can create a vulnerable HTML page by changing
Impact
Affected versions
0.4.1
0.4.2
0.4.3
0.4.4
0.4.4.post1
0.4.4.post2
0.4.5
0.4.6
0.4.6.post1
0.4.6.post2
0.4.7
0.4.8
+ 78 more Show less
0.5.0
0.5.1
0.6.0
0.6.1
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.4.post0
0.7.4.post1
0.7.5.post1
0.7.5.post2
0.8.0
0.8.0.post0
0.8.1
0.8.1.post0
0.8.2
0.8.2.post0
0.9.0
0.9.0.post2
0.9.0.post3
0.9.0.post4
0.9.0.post5
0.9.1
0.9.1.post0
0.9.1.post1
0.9.1.post2
1.0.0
1.0.0.post0
1.0.0.post1
1.0.0.post2
1.0.0.post3
1.0.1
1.0.2
1.0.2.post0
1.1.0
1.1.0rc0
1.1.1
1.10.0
1.10.0.post0
1.10.1
1.11.0
1.12.0
1.12.0.post0
1.12.1
1.13.0
1.13.1
1.14.0
1.14.0.post0
1.15.0
1.16.0
1.17.0
1.2
1.3
1.3.post0
1.3.post1
1.4
1.4.1
1.4.1.post0
1.4.1.post1
1.5.0
1.5.0.post0
1.6.0
1.7.0
1.7.1
1.7.2
1.7.3
1.8.0
1.8.1
1.8.2
1.8.2.post0
1.8.2.post1
1.9.0
1.9.1
1.9.1.post0
1.9.2
1.9.2.post0
Fixed in
1.18.0
References
Updated Jun 06, 2026 · Source: OSV.dev | ||
1.15.0
minor
4 CVEs
CVE-2026-22033
PYSEC-2026-1502
GHSA-2mq9-hm29-8qch
Jul 07, 2026
Label Studio is vulnerable to full account takeover by chaining Stored XSS + IDOR in User Profile via custom_hotkeys field
Critical
Network
Low
Low
None
PrologueThese vulnerabilities have been found and chained by DCODX-AI. Validation of the exploit chain has been confirmed manually. SummaryA persistent stored cross-site scripting (XSS) vulnerability exists in the custom_hotkeys functionality of the application. An authenticated attacker (or one who can trick a user/administrator into updating their custom_hotkeys) can inject JavaScript code that executes in other users’ browsers when those users load any page using the DetailsWithin
Here, user.custom_hotkeys is run through json_dumps_ensure_ascii (in In
The serializer allows
When another user loads a page using templates/base.html (for example PoC
Example request
Example response
ImpactExploitation impact:
Who is impacted:
Affected versions
0.4.1
0.4.2
0.4.3
0.4.4
0.4.4.post1
0.4.4.post2
0.4.5
0.4.6
0.4.6.post1
0.4.6.post2
0.4.7
0.4.8
+ 83 more Show less
0.5.0
0.5.1
0.6.0
0.6.1
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.4.post0
0.7.4.post1
0.7.5.post1
0.7.5.post2
0.8.0
0.8.0.post0
0.8.1
0.8.1.post0
0.8.2
0.8.2.post0
0.9.0
0.9.0.post2
0.9.0.post3
0.9.0.post4
0.9.0.post5
0.9.1
0.9.1.post0
0.9.1.post1
0.9.1.post2
1.0.0
1.0.0.post0
1.0.0.post1
1.0.0.post2
1.0.0.post3
1.0.1
1.0.2
1.0.2.post0
1.1.0
1.1.0rc0
1.1.1
1.10.0
1.10.0.post0
1.10.1
1.11.0
1.12.0
1.12.0.post0
1.12.1
1.13.0
1.13.1
1.14.0
1.14.0.post0
1.15.0
1.16.0
1.17.0
1.18.0
1.19.0
1.2
1.20.0
1.21.0
1.22.0
1.3
1.3.post0
1.3.post1
1.4
1.4.1
1.4.1.post0
1.4.1.post1
1.5.0
1.5.0.post0
1.6.0
1.7.0
1.7.1
1.7.2
1.7.3
1.8.0
1.8.1
1.8.2
1.8.2.post0
1.8.2.post1
1.9.0
1.9.1
1.9.1.post0
1.9.2
1.9.2.post0
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-25297
PYSEC-2026-1503
GHSA-m238-fmcw-wh58
Jul 07, 2026
Label Studio allows Server-Side Request Forgery in the S3 Storage Endpoint
8.6
/ 10
High
Network
Low
None
None
Changed
High
None
None
DescriptionLabel Studio's S3 storage integration feature contains a Server-Side Request Forgery (SSRF) vulnerability in its endpoint configuration. When creating an S3 storage connection, the application allows users to specify a custom S3 endpoint URL via the s3_endpoint parameter. This endpoint URL is passed directly to the boto3 AWS SDK without proper validation or restrictions on the protocol or destination. The vulnerability allows an attacker to make the application send HTTP requests to arbitrary internal services by specifying them as the S3 endpoint. When the storage sync operation is triggered, the application attempts to make S3 API calls to the specified endpoint, effectively making HTTP requests to the target service and returning the response in error messages. This SSRF vulnerability enables attackers to bypass network segmentation and access internal services that should not be accessible from the external network. The vulnerability is particularly severe because error messages from failed requests contain the full response body, allowing data exfiltration from internal services. Steps to reproduce
The application will attempt to connect to the specified endpoint URL as if it were an S3 service. When the request fails due to invalid S3 API responses, the error message will contain the raw response from the internal service, allowing access to internal resources. Mitigations
ImpactThis vulnerability has high severity as it allows authenticated users to make requests to arbitrary internal services from the application server, potentially exposing sensitive internal resources and bypassing network segmentation. The inclusion of response data in error messages makes this particularly effective for data exfiltration. Affected versions
0.4.1
0.4.2
0.4.3
0.4.4
0.4.4.post1
0.4.4.post2
0.4.5
0.4.6
0.4.6.post1
0.4.6.post2
0.4.7
0.4.8
+ 76 more Show less
0.5.0
0.5.1
0.6.0
0.6.1
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.4.post0
0.7.4.post1
0.7.5.post1
0.7.5.post2
0.8.0
0.8.0.post0
0.8.1
0.8.1.post0
0.8.2
0.8.2.post0
0.9.0
0.9.0.post2
0.9.0.post3
0.9.0.post4
0.9.0.post5
0.9.1
0.9.1.post0
0.9.1.post1
0.9.1.post2
1.0.0
1.0.0.post0
1.0.0.post1
1.0.0.post2
1.0.0.post3
1.0.1
1.0.2
1.0.2.post0
1.1.0
1.1.0rc0
1.1.1
1.10.0
1.10.0.post0
1.10.1
1.11.0
1.12.0
1.12.0.post0
1.12.1
1.13.0
1.13.1
1.14.0
1.14.0.post0
1.15.0
1.2
1.3
1.3.post0
1.3.post1
1.4
1.4.1
1.4.1.post0
1.4.1.post1
1.5.0
1.5.0.post0
1.6.0
1.7.0
1.7.1
1.7.2
1.7.3
1.8.0
1.8.1
1.8.2
1.8.2.post0
1.8.2.post1
1.9.0
1.9.1
1.9.1.post0
1.9.2
1.9.2.post0
Fixed in
1.16.0
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-25296
PYSEC-2026-1504
GHSA-wpq5-3366-mqw4
Jul 07, 2026
Label Studio allows Cross-Site Scripting (XSS) via GET request to `/projects/upload-example` endpoint
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
DescriptionLabel Studio's The vulnerability exists because the upload-example endpoint renders user-provided HTML content without proper sanitization on a GET request. This allows attackers to inject and execute arbitrary JavaScript in victims' browsers by getting them to visit a maliciously crafted URL. This is considered vulnerable because it enables attackers to execute JavaScript in victims' contexts, potentially allowing theft of sensitive data, session hijacking, or other malicious actions. Steps to reproduce
When executed, the payload causes the application to render an HTML page containing an img tag that fails to load, triggering the onerror event handler which executes base64-decoded JavaScript, demonstrating successful XSS execution in the victim's browser. Mitigations
ImpactThe vulnerability requires no special privileges and can be exploited by getting a victim to visit a crafted URL. The impact is high as it allows arbitrary JavaScript execution in victims' browsers, potentially exposing sensitive data or enabling account takeover through session theft. Affected versions
0.4.1
0.4.2
0.4.3
0.4.4
0.4.4.post1
0.4.4.post2
0.4.5
0.4.6
0.4.6.post1
0.4.6.post2
0.4.7
0.4.8
+ 76 more Show less
0.5.0
0.5.1
0.6.0
0.6.1
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.4.post0
0.7.4.post1
0.7.5.post1
0.7.5.post2
0.8.0
0.8.0.post0
0.8.1
0.8.1.post0
0.8.2
0.8.2.post0
0.9.0
0.9.0.post2
0.9.0.post3
0.9.0.post4
0.9.0.post5
0.9.1
0.9.1.post0
0.9.1.post1
0.9.1.post2
1.0.0
1.0.0.post0
1.0.0.post1
1.0.0.post2
1.0.0.post3
1.0.1
1.0.2
1.0.2.post0
1.1.0
1.1.0rc0
1.1.1
1.10.0
1.10.0.post0
1.10.1
1.11.0
1.12.0
1.12.0.post0
1.12.1
1.13.0
1.13.1
1.14.0
1.14.0.post0
1.15.0
1.2
1.3
1.3.post0
1.3.post1
1.4
1.4.1
1.4.1.post0
1.4.1.post1
1.5.0
1.5.0.post0
1.6.0
1.7.0
1.7.1
1.7.2
1.7.3
1.8.0
1.8.1
1.8.2
1.8.2.post0
1.8.2.post1
1.9.0
1.9.1
1.9.1.post0
1.9.2
1.9.2.post0
Fixed in
1.16.0
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-47783
GHSA-8jhr-wpcm-hh4h
PYSEC-2025-124
May 15, 2025
label-studio vulnerable to Cross-Site Scripting (Reflected) via the label_config parameter.
High
Network
Low
None
SummaryThe vulnerability allows an attacker to inject a malicious script into the context of a web page, which can lead to data theft, unauthorized actions on behalf of the user, and other attacks. DetailsThe vulnerability is reproducible when sending a properly formatted request to the
The vulnerability is specifically located in line 57, where HttpResponse is used.
PoCSend the following request after changing the
Or you can create a vulnerable HTML page by changing
Impact
Affected versions
0.4.1
0.4.2
0.4.3
0.4.4
0.4.4.post1
0.4.4.post2
0.4.5
0.4.6
0.4.6.post1
0.4.6.post2
0.4.7
0.4.8
+ 78 more Show less
0.5.0
0.5.1
0.6.0
0.6.1
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.4.post0
0.7.4.post1
0.7.5.post1
0.7.5.post2
0.8.0
0.8.0.post0
0.8.1
0.8.1.post0
0.8.2
0.8.2.post0
0.9.0
0.9.0.post2
0.9.0.post3
0.9.0.post4
0.9.0.post5
0.9.1
0.9.1.post0
0.9.1.post1
0.9.1.post2
1.0.0
1.0.0.post0
1.0.0.post1
1.0.0.post2
1.0.0.post3
1.0.1
1.0.2
1.0.2.post0
1.1.0
1.1.0rc0
1.1.1
1.10.0
1.10.0.post0
1.10.1
1.11.0
1.12.0
1.12.0.post0
1.12.1
1.13.0
1.13.1
1.14.0
1.14.0.post0
1.15.0
1.16.0
1.17.0
1.2
1.3
1.3.post0
1.3.post1
1.4
1.4.1
1.4.1.post0
1.4.1.post1
1.5.0
1.5.0.post0
1.6.0
1.7.0
1.7.1
1.7.2
1.7.3
1.8.0
1.8.1
1.8.2
1.8.2.post0
1.8.2.post1
1.9.0
1.9.1
1.9.1.post0
1.9.2
1.9.2.post0
Fixed in
1.18.0
References
Updated Jun 06, 2026 · Source: OSV.dev | ||
1.14.0.post0
pre
4 CVEs
CVE-2026-22033
PYSEC-2026-1502
GHSA-2mq9-hm29-8qch
Jul 07, 2026
Label Studio is vulnerable to full account takeover by chaining Stored XSS + IDOR in User Profile via custom_hotkeys field
Critical
Network
Low
Low
None
PrologueThese vulnerabilities have been found and chained by DCODX-AI. Validation of the exploit chain has been confirmed manually. SummaryA persistent stored cross-site scripting (XSS) vulnerability exists in the custom_hotkeys functionality of the application. An authenticated attacker (or one who can trick a user/administrator into updating their custom_hotkeys) can inject JavaScript code that executes in other users’ browsers when those users load any page using the DetailsWithin
Here, user.custom_hotkeys is run through json_dumps_ensure_ascii (in In
The serializer allows
When another user loads a page using templates/base.html (for example PoC
Example request
Example response
ImpactExploitation impact:
Who is impacted:
Affected versions
0.4.1
0.4.2
0.4.3
0.4.4
0.4.4.post1
0.4.4.post2
0.4.5
0.4.6
0.4.6.post1
0.4.6.post2
0.4.7
0.4.8
+ 83 more Show less
0.5.0
0.5.1
0.6.0
0.6.1
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.4.post0
0.7.4.post1
0.7.5.post1
0.7.5.post2
0.8.0
0.8.0.post0
0.8.1
0.8.1.post0
0.8.2
0.8.2.post0
0.9.0
0.9.0.post2
0.9.0.post3
0.9.0.post4
0.9.0.post5
0.9.1
0.9.1.post0
0.9.1.post1
0.9.1.post2
1.0.0
1.0.0.post0
1.0.0.post1
1.0.0.post2
1.0.0.post3
1.0.1
1.0.2
1.0.2.post0
1.1.0
1.1.0rc0
1.1.1
1.10.0
1.10.0.post0
1.10.1
1.11.0
1.12.0
1.12.0.post0
1.12.1
1.13.0
1.13.1
1.14.0
1.14.0.post0
1.15.0
1.16.0
1.17.0
1.18.0
1.19.0
1.2
1.20.0
1.21.0
1.22.0
1.3
1.3.post0
1.3.post1
1.4
1.4.1
1.4.1.post0
1.4.1.post1
1.5.0
1.5.0.post0
1.6.0
1.7.0
1.7.1
1.7.2
1.7.3
1.8.0
1.8.1
1.8.2
1.8.2.post0
1.8.2.post1
1.9.0
1.9.1
1.9.1.post0
1.9.2
1.9.2.post0
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-25297
PYSEC-2026-1503
GHSA-m238-fmcw-wh58
Jul 07, 2026
Label Studio allows Server-Side Request Forgery in the S3 Storage Endpoint
8.6
/ 10
High
Network
Low
None
None
Changed
High
None
None
DescriptionLabel Studio's S3 storage integration feature contains a Server-Side Request Forgery (SSRF) vulnerability in its endpoint configuration. When creating an S3 storage connection, the application allows users to specify a custom S3 endpoint URL via the s3_endpoint parameter. This endpoint URL is passed directly to the boto3 AWS SDK without proper validation or restrictions on the protocol or destination. The vulnerability allows an attacker to make the application send HTTP requests to arbitrary internal services by specifying them as the S3 endpoint. When the storage sync operation is triggered, the application attempts to make S3 API calls to the specified endpoint, effectively making HTTP requests to the target service and returning the response in error messages. This SSRF vulnerability enables attackers to bypass network segmentation and access internal services that should not be accessible from the external network. The vulnerability is particularly severe because error messages from failed requests contain the full response body, allowing data exfiltration from internal services. Steps to reproduce
The application will attempt to connect to the specified endpoint URL as if it were an S3 service. When the request fails due to invalid S3 API responses, the error message will contain the raw response from the internal service, allowing access to internal resources. Mitigations
ImpactThis vulnerability has high severity as it allows authenticated users to make requests to arbitrary internal services from the application server, potentially exposing sensitive internal resources and bypassing network segmentation. The inclusion of response data in error messages makes this particularly effective for data exfiltration. Affected versions
0.4.1
0.4.2
0.4.3
0.4.4
0.4.4.post1
0.4.4.post2
0.4.5
0.4.6
0.4.6.post1
0.4.6.post2
0.4.7
0.4.8
+ 76 more Show less
0.5.0
0.5.1
0.6.0
0.6.1
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.4.post0
0.7.4.post1
0.7.5.post1
0.7.5.post2
0.8.0
0.8.0.post0
0.8.1
0.8.1.post0
0.8.2
0.8.2.post0
0.9.0
0.9.0.post2
0.9.0.post3
0.9.0.post4
0.9.0.post5
0.9.1
0.9.1.post0
0.9.1.post1
0.9.1.post2
1.0.0
1.0.0.post0
1.0.0.post1
1.0.0.post2
1.0.0.post3
1.0.1
1.0.2
1.0.2.post0
1.1.0
1.1.0rc0
1.1.1
1.10.0
1.10.0.post0
1.10.1
1.11.0
1.12.0
1.12.0.post0
1.12.1
1.13.0
1.13.1
1.14.0
1.14.0.post0
1.15.0
1.2
1.3
1.3.post0
1.3.post1
1.4
1.4.1
1.4.1.post0
1.4.1.post1
1.5.0
1.5.0.post0
1.6.0
1.7.0
1.7.1
1.7.2
1.7.3
1.8.0
1.8.1
1.8.2
1.8.2.post0
1.8.2.post1
1.9.0
1.9.1
1.9.1.post0
1.9.2
1.9.2.post0
Fixed in
1.16.0
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-25296
PYSEC-2026-1504
GHSA-wpq5-3366-mqw4
Jul 07, 2026
Label Studio allows Cross-Site Scripting (XSS) via GET request to `/projects/upload-example` endpoint
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
DescriptionLabel Studio's The vulnerability exists because the upload-example endpoint renders user-provided HTML content without proper sanitization on a GET request. This allows attackers to inject and execute arbitrary JavaScript in victims' browsers by getting them to visit a maliciously crafted URL. This is considered vulnerable because it enables attackers to execute JavaScript in victims' contexts, potentially allowing theft of sensitive data, session hijacking, or other malicious actions. Steps to reproduce
When executed, the payload causes the application to render an HTML page containing an img tag that fails to load, triggering the onerror event handler which executes base64-decoded JavaScript, demonstrating successful XSS execution in the victim's browser. Mitigations
ImpactThe vulnerability requires no special privileges and can be exploited by getting a victim to visit a crafted URL. The impact is high as it allows arbitrary JavaScript execution in victims' browsers, potentially exposing sensitive data or enabling account takeover through session theft. Affected versions
0.4.1
0.4.2
0.4.3
0.4.4
0.4.4.post1
0.4.4.post2
0.4.5
0.4.6
0.4.6.post1
0.4.6.post2
0.4.7
0.4.8
+ 76 more Show less
0.5.0
0.5.1
0.6.0
0.6.1
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.4.post0
0.7.4.post1
0.7.5.post1
0.7.5.post2
0.8.0
0.8.0.post0
0.8.1
0.8.1.post0
0.8.2
0.8.2.post0
0.9.0
0.9.0.post2
0.9.0.post3
0.9.0.post4
0.9.0.post5
0.9.1
0.9.1.post0
0.9.1.post1
0.9.1.post2
1.0.0
1.0.0.post0
1.0.0.post1
1.0.0.post2
1.0.0.post3
1.0.1
1.0.2
1.0.2.post0
1.1.0
1.1.0rc0
1.1.1
1.10.0
1.10.0.post0
1.10.1
1.11.0
1.12.0
1.12.0.post0
1.12.1
1.13.0
1.13.1
1.14.0
1.14.0.post0
1.15.0
1.2
1.3
1.3.post0
1.3.post1
1.4
1.4.1
1.4.1.post0
1.4.1.post1
1.5.0
1.5.0.post0
1.6.0
1.7.0
1.7.1
1.7.2
1.7.3
1.8.0
1.8.1
1.8.2
1.8.2.post0
1.8.2.post1
1.9.0
1.9.1
1.9.1.post0
1.9.2
1.9.2.post0
Fixed in
1.16.0
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-47783
GHSA-8jhr-wpcm-hh4h
PYSEC-2025-124
May 15, 2025
label-studio vulnerable to Cross-Site Scripting (Reflected) via the label_config parameter.
High
Network
Low
None
SummaryThe vulnerability allows an attacker to inject a malicious script into the context of a web page, which can lead to data theft, unauthorized actions on behalf of the user, and other attacks. DetailsThe vulnerability is reproducible when sending a properly formatted request to the
The vulnerability is specifically located in line 57, where HttpResponse is used.
PoCSend the following request after changing the
Or you can create a vulnerable HTML page by changing
Impact
Affected versions
0.4.1
0.4.2
0.4.3
0.4.4
0.4.4.post1
0.4.4.post2
0.4.5
0.4.6
0.4.6.post1
0.4.6.post2
0.4.7
0.4.8
+ 78 more Show less
0.5.0
0.5.1
0.6.0
0.6.1
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.4.post0
0.7.4.post1
0.7.5.post1
0.7.5.post2
0.8.0
0.8.0.post0
0.8.1
0.8.1.post0
0.8.2
0.8.2.post0
0.9.0
0.9.0.post2
0.9.0.post3
0.9.0.post4
0.9.0.post5
0.9.1
0.9.1.post0
0.9.1.post1
0.9.1.post2
1.0.0
1.0.0.post0
1.0.0.post1
1.0.0.post2
1.0.0.post3
1.0.1
1.0.2
1.0.2.post0
1.1.0
1.1.0rc0
1.1.1
1.10.0
1.10.0.post0
1.10.1
1.11.0
1.12.0
1.12.0.post0
1.12.1
1.13.0
1.13.1
1.14.0
1.14.0.post0
1.15.0
1.16.0
1.17.0
1.2
1.3
1.3.post0
1.3.post1
1.4
1.4.1
1.4.1.post0
1.4.1.post1
1.5.0
1.5.0.post0
1.6.0
1.7.0
1.7.1
1.7.2
1.7.3
1.8.0
1.8.1
1.8.2
1.8.2.post0
1.8.2.post1
1.9.0
1.9.1
1.9.1.post0
1.9.2
1.9.2.post0
Fixed in
1.18.0
References
Updated Jun 06, 2026 · Source: OSV.dev | ||
1.14.0
minor
4 CVEs
CVE-2026-22033
PYSEC-2026-1502
GHSA-2mq9-hm29-8qch
Jul 07, 2026
Label Studio is vulnerable to full account takeover by chaining Stored XSS + IDOR in User Profile via custom_hotkeys field
Critical
Network
Low
Low
None
PrologueThese vulnerabilities have been found and chained by DCODX-AI. Validation of the exploit chain has been confirmed manually. SummaryA persistent stored cross-site scripting (XSS) vulnerability exists in the custom_hotkeys functionality of the application. An authenticated attacker (or one who can trick a user/administrator into updating their custom_hotkeys) can inject JavaScript code that executes in other users’ browsers when those users load any page using the DetailsWithin
Here, user.custom_hotkeys is run through json_dumps_ensure_ascii (in In
The serializer allows
When another user loads a page using templates/base.html (for example PoC
Example request
Example response
ImpactExploitation impact:
Who is impacted:
Affected versions
0.4.1
0.4.2
0.4.3
0.4.4
0.4.4.post1
0.4.4.post2
0.4.5
0.4.6
0.4.6.post1
0.4.6.post2
0.4.7
0.4.8
+ 83 more Show less
0.5.0
0.5.1
0.6.0
0.6.1
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.4.post0
0.7.4.post1
0.7.5.post1
0.7.5.post2
0.8.0
0.8.0.post0
0.8.1
0.8.1.post0
0.8.2
0.8.2.post0
0.9.0
0.9.0.post2
0.9.0.post3
0.9.0.post4
0.9.0.post5
0.9.1
0.9.1.post0
0.9.1.post1
0.9.1.post2
1.0.0
1.0.0.post0
1.0.0.post1
1.0.0.post2
1.0.0.post3
1.0.1
1.0.2
1.0.2.post0
1.1.0
1.1.0rc0
1.1.1
1.10.0
1.10.0.post0
1.10.1
1.11.0
1.12.0
1.12.0.post0
1.12.1
1.13.0
1.13.1
1.14.0
1.14.0.post0
1.15.0
1.16.0
1.17.0
1.18.0
1.19.0
1.2
1.20.0
1.21.0
1.22.0
1.3
1.3.post0
1.3.post1
1.4
1.4.1
1.4.1.post0
1.4.1.post1
1.5.0
1.5.0.post0
1.6.0
1.7.0
1.7.1
1.7.2
1.7.3
1.8.0
1.8.1
1.8.2
1.8.2.post0
1.8.2.post1
1.9.0
1.9.1
1.9.1.post0
1.9.2
1.9.2.post0
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-25297
PYSEC-2026-1503
GHSA-m238-fmcw-wh58
Jul 07, 2026
Label Studio allows Server-Side Request Forgery in the S3 Storage Endpoint
8.6
/ 10
High
Network
Low
None
None
Changed
High
None
None
DescriptionLabel Studio's S3 storage integration feature contains a Server-Side Request Forgery (SSRF) vulnerability in its endpoint configuration. When creating an S3 storage connection, the application allows users to specify a custom S3 endpoint URL via the s3_endpoint parameter. This endpoint URL is passed directly to the boto3 AWS SDK without proper validation or restrictions on the protocol or destination. The vulnerability allows an attacker to make the application send HTTP requests to arbitrary internal services by specifying them as the S3 endpoint. When the storage sync operation is triggered, the application attempts to make S3 API calls to the specified endpoint, effectively making HTTP requests to the target service and returning the response in error messages. This SSRF vulnerability enables attackers to bypass network segmentation and access internal services that should not be accessible from the external network. The vulnerability is particularly severe because error messages from failed requests contain the full response body, allowing data exfiltration from internal services. Steps to reproduce
The application will attempt to connect to the specified endpoint URL as if it were an S3 service. When the request fails due to invalid S3 API responses, the error message will contain the raw response from the internal service, allowing access to internal resources. Mitigations
ImpactThis vulnerability has high severity as it allows authenticated users to make requests to arbitrary internal services from the application server, potentially exposing sensitive internal resources and bypassing network segmentation. The inclusion of response data in error messages makes this particularly effective for data exfiltration. Affected versions
0.4.1
0.4.2
0.4.3
0.4.4
0.4.4.post1
0.4.4.post2
0.4.5
0.4.6
0.4.6.post1
0.4.6.post2
0.4.7
0.4.8
+ 76 more Show less
0.5.0
0.5.1
0.6.0
0.6.1
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.4.post0
0.7.4.post1
0.7.5.post1
0.7.5.post2
0.8.0
0.8.0.post0
0.8.1
0.8.1.post0
0.8.2
0.8.2.post0
0.9.0
0.9.0.post2
0.9.0.post3
0.9.0.post4
0.9.0.post5
0.9.1
0.9.1.post0
0.9.1.post1
0.9.1.post2
1.0.0
1.0.0.post0
1.0.0.post1
1.0.0.post2
1.0.0.post3
1.0.1
1.0.2
1.0.2.post0
1.1.0
1.1.0rc0
1.1.1
1.10.0
1.10.0.post0
1.10.1
1.11.0
1.12.0
1.12.0.post0
1.12.1
1.13.0
1.13.1
1.14.0
1.14.0.post0
1.15.0
1.2
1.3
1.3.post0
1.3.post1
1.4
1.4.1
1.4.1.post0
1.4.1.post1
1.5.0
1.5.0.post0
1.6.0
1.7.0
1.7.1
1.7.2
1.7.3
1.8.0
1.8.1
1.8.2
1.8.2.post0
1.8.2.post1
1.9.0
1.9.1
1.9.1.post0
1.9.2
1.9.2.post0
Fixed in
1.16.0
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-25296
PYSEC-2026-1504
GHSA-wpq5-3366-mqw4
Jul 07, 2026
Label Studio allows Cross-Site Scripting (XSS) via GET request to `/projects/upload-example` endpoint
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
DescriptionLabel Studio's The vulnerability exists because the upload-example endpoint renders user-provided HTML content without proper sanitization on a GET request. This allows attackers to inject and execute arbitrary JavaScript in victims' browsers by getting them to visit a maliciously crafted URL. This is considered vulnerable because it enables attackers to execute JavaScript in victims' contexts, potentially allowing theft of sensitive data, session hijacking, or other malicious actions. Steps to reproduce
When executed, the payload causes the application to render an HTML page containing an img tag that fails to load, triggering the onerror event handler which executes base64-decoded JavaScript, demonstrating successful XSS execution in the victim's browser. Mitigations
ImpactThe vulnerability requires no special privileges and can be exploited by getting a victim to visit a crafted URL. The impact is high as it allows arbitrary JavaScript execution in victims' browsers, potentially exposing sensitive data or enabling account takeover through session theft. Affected versions
0.4.1
0.4.2
0.4.3
0.4.4
0.4.4.post1
0.4.4.post2
0.4.5
0.4.6
0.4.6.post1
0.4.6.post2
0.4.7
0.4.8
+ 76 more Show less
0.5.0
0.5.1
0.6.0
0.6.1
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.4.post0
0.7.4.post1
0.7.5.post1
0.7.5.post2
0.8.0
0.8.0.post0
0.8.1
0.8.1.post0
0.8.2
0.8.2.post0
0.9.0
0.9.0.post2
0.9.0.post3
0.9.0.post4
0.9.0.post5
0.9.1
0.9.1.post0
0.9.1.post1
0.9.1.post2
1.0.0
1.0.0.post0
1.0.0.post1
1.0.0.post2
1.0.0.post3
1.0.1
1.0.2
1.0.2.post0
1.1.0
1.1.0rc0
1.1.1
1.10.0
1.10.0.post0
1.10.1
1.11.0
1.12.0
1.12.0.post0
1.12.1
1.13.0
1.13.1
1.14.0
1.14.0.post0
1.15.0
1.2
1.3
1.3.post0
1.3.post1
1.4
1.4.1
1.4.1.post0
1.4.1.post1
1.5.0
1.5.0.post0
1.6.0
1.7.0
1.7.1
1.7.2
1.7.3
1.8.0
1.8.1
1.8.2
1.8.2.post0
1.8.2.post1
1.9.0
1.9.1
1.9.1.post0
1.9.2
1.9.2.post0
Fixed in
1.16.0
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-47783
GHSA-8jhr-wpcm-hh4h
PYSEC-2025-124
May 15, 2025
label-studio vulnerable to Cross-Site Scripting (Reflected) via the label_config parameter.
High
Network
Low
None
SummaryThe vulnerability allows an attacker to inject a malicious script into the context of a web page, which can lead to data theft, unauthorized actions on behalf of the user, and other attacks. DetailsThe vulnerability is reproducible when sending a properly formatted request to the
The vulnerability is specifically located in line 57, where HttpResponse is used.
PoCSend the following request after changing the
Or you can create a vulnerable HTML page by changing
Impact
Affected versions
0.4.1
0.4.2
0.4.3
0.4.4
0.4.4.post1
0.4.4.post2
0.4.5
0.4.6
0.4.6.post1
0.4.6.post2
0.4.7
0.4.8
+ 78 more Show less
0.5.0
0.5.1
0.6.0
0.6.1
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.4.post0
0.7.4.post1
0.7.5.post1
0.7.5.post2
0.8.0
0.8.0.post0
0.8.1
0.8.1.post0
0.8.2
0.8.2.post0
0.9.0
0.9.0.post2
0.9.0.post3
0.9.0.post4
0.9.0.post5
0.9.1
0.9.1.post0
0.9.1.post1
0.9.1.post2
1.0.0
1.0.0.post0
1.0.0.post1
1.0.0.post2
1.0.0.post3
1.0.1
1.0.2
1.0.2.post0
1.1.0
1.1.0rc0
1.1.1
1.10.0
1.10.0.post0
1.10.1
1.11.0
1.12.0
1.12.0.post0
1.12.1
1.13.0
1.13.1
1.14.0
1.14.0.post0
1.15.0
1.16.0
1.17.0
1.2
1.3
1.3.post0
1.3.post1
1.4
1.4.1
1.4.1.post0
1.4.1.post1
1.5.0
1.5.0.post0
1.6.0
1.7.0
1.7.1
1.7.2
1.7.3
1.8.0
1.8.1
1.8.2
1.8.2.post0
1.8.2.post1
1.9.0
1.9.1
1.9.1.post0
1.9.2
1.9.2.post0
Fixed in
1.18.0
References
Updated Jun 06, 2026 · Source: OSV.dev | ||
1.13.1
patch
4 CVEs
CVE-2026-22033
PYSEC-2026-1502
GHSA-2mq9-hm29-8qch
Jul 07, 2026
Label Studio is vulnerable to full account takeover by chaining Stored XSS + IDOR in User Profile via custom_hotkeys field
Critical
Network
Low
Low
None
PrologueThese vulnerabilities have been found and chained by DCODX-AI. Validation of the exploit chain has been confirmed manually. SummaryA persistent stored cross-site scripting (XSS) vulnerability exists in the custom_hotkeys functionality of the application. An authenticated attacker (or one who can trick a user/administrator into updating their custom_hotkeys) can inject JavaScript code that executes in other users’ browsers when those users load any page using the DetailsWithin
Here, user.custom_hotkeys is run through json_dumps_ensure_ascii (in In
The serializer allows
When another user loads a page using templates/base.html (for example PoC
Example request
Example response
ImpactExploitation impact:
Who is impacted:
Affected versions
0.4.1
0.4.2
0.4.3
0.4.4
0.4.4.post1
0.4.4.post2
0.4.5
0.4.6
0.4.6.post1
0.4.6.post2
0.4.7
0.4.8
+ 83 more Show less
0.5.0
0.5.1
0.6.0
0.6.1
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.4.post0
0.7.4.post1
0.7.5.post1
0.7.5.post2
0.8.0
0.8.0.post0
0.8.1
0.8.1.post0
0.8.2
0.8.2.post0
0.9.0
0.9.0.post2
0.9.0.post3
0.9.0.post4
0.9.0.post5
0.9.1
0.9.1.post0
0.9.1.post1
0.9.1.post2
1.0.0
1.0.0.post0
1.0.0.post1
1.0.0.post2
1.0.0.post3
1.0.1
1.0.2
1.0.2.post0
1.1.0
1.1.0rc0
1.1.1
1.10.0
1.10.0.post0
1.10.1
1.11.0
1.12.0
1.12.0.post0
1.12.1
1.13.0
1.13.1
1.14.0
1.14.0.post0
1.15.0
1.16.0
1.17.0
1.18.0
1.19.0
1.2
1.20.0
1.21.0
1.22.0
1.3
1.3.post0
1.3.post1
1.4
1.4.1
1.4.1.post0
1.4.1.post1
1.5.0
1.5.0.post0
1.6.0
1.7.0
1.7.1
1.7.2
1.7.3
1.8.0
1.8.1
1.8.2
1.8.2.post0
1.8.2.post1
1.9.0
1.9.1
1.9.1.post0
1.9.2
1.9.2.post0
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-25297
PYSEC-2026-1503
GHSA-m238-fmcw-wh58
Jul 07, 2026
Label Studio allows Server-Side Request Forgery in the S3 Storage Endpoint
8.6
/ 10
High
Network
Low
None
None
Changed
High
None
None
DescriptionLabel Studio's S3 storage integration feature contains a Server-Side Request Forgery (SSRF) vulnerability in its endpoint configuration. When creating an S3 storage connection, the application allows users to specify a custom S3 endpoint URL via the s3_endpoint parameter. This endpoint URL is passed directly to the boto3 AWS SDK without proper validation or restrictions on the protocol or destination. The vulnerability allows an attacker to make the application send HTTP requests to arbitrary internal services by specifying them as the S3 endpoint. When the storage sync operation is triggered, the application attempts to make S3 API calls to the specified endpoint, effectively making HTTP requests to the target service and returning the response in error messages. This SSRF vulnerability enables attackers to bypass network segmentation and access internal services that should not be accessible from the external network. The vulnerability is particularly severe because error messages from failed requests contain the full response body, allowing data exfiltration from internal services. Steps to reproduce
The application will attempt to connect to the specified endpoint URL as if it were an S3 service. When the request fails due to invalid S3 API responses, the error message will contain the raw response from the internal service, allowing access to internal resources. Mitigations
ImpactThis vulnerability has high severity as it allows authenticated users to make requests to arbitrary internal services from the application server, potentially exposing sensitive internal resources and bypassing network segmentation. The inclusion of response data in error messages makes this particularly effective for data exfiltration. Affected versions
0.4.1
0.4.2
0.4.3
0.4.4
0.4.4.post1
0.4.4.post2
0.4.5
0.4.6
0.4.6.post1
0.4.6.post2
0.4.7
0.4.8
+ 76 more Show less
0.5.0
0.5.1
0.6.0
0.6.1
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.4.post0
0.7.4.post1
0.7.5.post1
0.7.5.post2
0.8.0
0.8.0.post0
0.8.1
0.8.1.post0
0.8.2
0.8.2.post0
0.9.0
0.9.0.post2
0.9.0.post3
0.9.0.post4
0.9.0.post5
0.9.1
0.9.1.post0
0.9.1.post1
0.9.1.post2
1.0.0
1.0.0.post0
1.0.0.post1
1.0.0.post2
1.0.0.post3
1.0.1
1.0.2
1.0.2.post0
1.1.0
1.1.0rc0
1.1.1
1.10.0
1.10.0.post0
1.10.1
1.11.0
1.12.0
1.12.0.post0
1.12.1
1.13.0
1.13.1
1.14.0
1.14.0.post0
1.15.0
1.2
1.3
1.3.post0
1.3.post1
1.4
1.4.1
1.4.1.post0
1.4.1.post1
1.5.0
1.5.0.post0
1.6.0
1.7.0
1.7.1
1.7.2
1.7.3
1.8.0
1.8.1
1.8.2
1.8.2.post0
1.8.2.post1
1.9.0
1.9.1
1.9.1.post0
1.9.2
1.9.2.post0
Fixed in
1.16.0
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-25296
PYSEC-2026-1504
GHSA-wpq5-3366-mqw4
Jul 07, 2026
Label Studio allows Cross-Site Scripting (XSS) via GET request to `/projects/upload-example` endpoint
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
DescriptionLabel Studio's The vulnerability exists because the upload-example endpoint renders user-provided HTML content without proper sanitization on a GET request. This allows attackers to inject and execute arbitrary JavaScript in victims' browsers by getting them to visit a maliciously crafted URL. This is considered vulnerable because it enables attackers to execute JavaScript in victims' contexts, potentially allowing theft of sensitive data, session hijacking, or other malicious actions. Steps to reproduce
When executed, the payload causes the application to render an HTML page containing an img tag that fails to load, triggering the onerror event handler which executes base64-decoded JavaScript, demonstrating successful XSS execution in the victim's browser. Mitigations
ImpactThe vulnerability requires no special privileges and can be exploited by getting a victim to visit a crafted URL. The impact is high as it allows arbitrary JavaScript execution in victims' browsers, potentially exposing sensitive data or enabling account takeover through session theft. Affected versions
0.4.1
0.4.2
0.4.3
0.4.4
0.4.4.post1
0.4.4.post2
0.4.5
0.4.6
0.4.6.post1
0.4.6.post2
0.4.7
0.4.8
+ 76 more Show less
0.5.0
0.5.1
0.6.0
0.6.1
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.4.post0
0.7.4.post1
0.7.5.post1
0.7.5.post2
0.8.0
0.8.0.post0
0.8.1
0.8.1.post0
0.8.2
0.8.2.post0
0.9.0
0.9.0.post2
0.9.0.post3
0.9.0.post4
0.9.0.post5
0.9.1
0.9.1.post0
0.9.1.post1
0.9.1.post2
1.0.0
1.0.0.post0
1.0.0.post1
1.0.0.post2
1.0.0.post3
1.0.1
1.0.2
1.0.2.post0
1.1.0
1.1.0rc0
1.1.1
1.10.0
1.10.0.post0
1.10.1
1.11.0
1.12.0
1.12.0.post0
1.12.1
1.13.0
1.13.1
1.14.0
1.14.0.post0
1.15.0
1.2
1.3
1.3.post0
1.3.post1
1.4
1.4.1
1.4.1.post0
1.4.1.post1
1.5.0
1.5.0.post0
1.6.0
1.7.0
1.7.1
1.7.2
1.7.3
1.8.0
1.8.1
1.8.2
1.8.2.post0
1.8.2.post1
1.9.0
1.9.1
1.9.1.post0
1.9.2
1.9.2.post0
Fixed in
1.16.0
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-47783
GHSA-8jhr-wpcm-hh4h
PYSEC-2025-124
May 15, 2025
label-studio vulnerable to Cross-Site Scripting (Reflected) via the label_config parameter.
High
Network
Low
None
SummaryThe vulnerability allows an attacker to inject a malicious script into the context of a web page, which can lead to data theft, unauthorized actions on behalf of the user, and other attacks. DetailsThe vulnerability is reproducible when sending a properly formatted request to the
The vulnerability is specifically located in line 57, where HttpResponse is used.
PoCSend the following request after changing the
Or you can create a vulnerable HTML page by changing
Impact
Affected versions
0.4.1
0.4.2
0.4.3
0.4.4
0.4.4.post1
0.4.4.post2
0.4.5
0.4.6
0.4.6.post1
0.4.6.post2
0.4.7
0.4.8
+ 78 more Show less
0.5.0
0.5.1
0.6.0
0.6.1
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.4.post0
0.7.4.post1
0.7.5.post1
0.7.5.post2
0.8.0
0.8.0.post0
0.8.1
0.8.1.post0
0.8.2
0.8.2.post0
0.9.0
0.9.0.post2
0.9.0.post3
0.9.0.post4
0.9.0.post5
0.9.1
0.9.1.post0
0.9.1.post1
0.9.1.post2
1.0.0
1.0.0.post0
1.0.0.post1
1.0.0.post2
1.0.0.post3
1.0.1
1.0.2
1.0.2.post0
1.1.0
1.1.0rc0
1.1.1
1.10.0
1.10.0.post0
1.10.1
1.11.0
1.12.0
1.12.0.post0
1.12.1
1.13.0
1.13.1
1.14.0
1.14.0.post0
1.15.0
1.16.0
1.17.0
1.2
1.3
1.3.post0
1.3.post1
1.4
1.4.1
1.4.1.post0
1.4.1.post1
1.5.0
1.5.0.post0
1.6.0
1.7.0
1.7.1
1.7.2
1.7.3
1.8.0
1.8.1
1.8.2
1.8.2.post0
1.8.2.post1
1.9.0
1.9.1
1.9.1.post0
1.9.2
1.9.2.post0
Fixed in
1.18.0
References
Updated Jun 06, 2026 · Source: OSV.dev | ||
1.13.0
minor
4 CVEs
CVE-2026-22033
PYSEC-2026-1502
GHSA-2mq9-hm29-8qch
Jul 07, 2026
Label Studio is vulnerable to full account takeover by chaining Stored XSS + IDOR in User Profile via custom_hotkeys field
Critical
Network
Low
Low
None
PrologueThese vulnerabilities have been found and chained by DCODX-AI. Validation of the exploit chain has been confirmed manually. SummaryA persistent stored cross-site scripting (XSS) vulnerability exists in the custom_hotkeys functionality of the application. An authenticated attacker (or one who can trick a user/administrator into updating their custom_hotkeys) can inject JavaScript code that executes in other users’ browsers when those users load any page using the DetailsWithin
Here, user.custom_hotkeys is run through json_dumps_ensure_ascii (in In
The serializer allows
When another user loads a page using templates/base.html (for example PoC
Example request
Example response
ImpactExploitation impact:
Who is impacted:
Affected versions
0.4.1
0.4.2
0.4.3
0.4.4
0.4.4.post1
0.4.4.post2
0.4.5
0.4.6
0.4.6.post1
0.4.6.post2
0.4.7
0.4.8
+ 83 more Show less
0.5.0
0.5.1
0.6.0
0.6.1
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.4.post0
0.7.4.post1
0.7.5.post1
0.7.5.post2
0.8.0
0.8.0.post0
0.8.1
0.8.1.post0
0.8.2
0.8.2.post0
0.9.0
0.9.0.post2
0.9.0.post3
0.9.0.post4
0.9.0.post5
0.9.1
0.9.1.post0
0.9.1.post1
0.9.1.post2
1.0.0
1.0.0.post0
1.0.0.post1
1.0.0.post2
1.0.0.post3
1.0.1
1.0.2
1.0.2.post0
1.1.0
1.1.0rc0
1.1.1
1.10.0
1.10.0.post0
1.10.1
1.11.0
1.12.0
1.12.0.post0
1.12.1
1.13.0
1.13.1
1.14.0
1.14.0.post0
1.15.0
1.16.0
1.17.0
1.18.0
1.19.0
1.2
1.20.0
1.21.0
1.22.0
1.3
1.3.post0
1.3.post1
1.4
1.4.1
1.4.1.post0
1.4.1.post1
1.5.0
1.5.0.post0
1.6.0
1.7.0
1.7.1
1.7.2
1.7.3
1.8.0
1.8.1
1.8.2
1.8.2.post0
1.8.2.post1
1.9.0
1.9.1
1.9.1.post0
1.9.2
1.9.2.post0
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-25297
PYSEC-2026-1503
GHSA-m238-fmcw-wh58
Jul 07, 2026
Label Studio allows Server-Side Request Forgery in the S3 Storage Endpoint
8.6
/ 10
High
Network
Low
None
None
Changed
High
None
None
DescriptionLabel Studio's S3 storage integration feature contains a Server-Side Request Forgery (SSRF) vulnerability in its endpoint configuration. When creating an S3 storage connection, the application allows users to specify a custom S3 endpoint URL via the s3_endpoint parameter. This endpoint URL is passed directly to the boto3 AWS SDK without proper validation or restrictions on the protocol or destination. The vulnerability allows an attacker to make the application send HTTP requests to arbitrary internal services by specifying them as the S3 endpoint. When the storage sync operation is triggered, the application attempts to make S3 API calls to the specified endpoint, effectively making HTTP requests to the target service and returning the response in error messages. This SSRF vulnerability enables attackers to bypass network segmentation and access internal services that should not be accessible from the external network. The vulnerability is particularly severe because error messages from failed requests contain the full response body, allowing data exfiltration from internal services. Steps to reproduce
The application will attempt to connect to the specified endpoint URL as if it were an S3 service. When the request fails due to invalid S3 API responses, the error message will contain the raw response from the internal service, allowing access to internal resources. Mitigations
ImpactThis vulnerability has high severity as it allows authenticated users to make requests to arbitrary internal services from the application server, potentially exposing sensitive internal resources and bypassing network segmentation. The inclusion of response data in error messages makes this particularly effective for data exfiltration. Affected versions
0.4.1
0.4.2
0.4.3
0.4.4
0.4.4.post1
0.4.4.post2
0.4.5
0.4.6
0.4.6.post1
0.4.6.post2
0.4.7
0.4.8
+ 76 more Show less
0.5.0
0.5.1
0.6.0
0.6.1
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.4.post0
0.7.4.post1
0.7.5.post1
0.7.5.post2
0.8.0
0.8.0.post0
0.8.1
0.8.1.post0
0.8.2
0.8.2.post0
0.9.0
0.9.0.post2
0.9.0.post3
0.9.0.post4
0.9.0.post5
0.9.1
0.9.1.post0
0.9.1.post1
0.9.1.post2
1.0.0
1.0.0.post0
1.0.0.post1
1.0.0.post2
1.0.0.post3
1.0.1
1.0.2
1.0.2.post0
1.1.0
1.1.0rc0
1.1.1
1.10.0
1.10.0.post0
1.10.1
1.11.0
1.12.0
1.12.0.post0
1.12.1
1.13.0
1.13.1
1.14.0
1.14.0.post0
1.15.0
1.2
1.3
1.3.post0
1.3.post1
1.4
1.4.1
1.4.1.post0
1.4.1.post1
1.5.0
1.5.0.post0
1.6.0
1.7.0
1.7.1
1.7.2
1.7.3
1.8.0
1.8.1
1.8.2
1.8.2.post0
1.8.2.post1
1.9.0
1.9.1
1.9.1.post0
1.9.2
1.9.2.post0
Fixed in
1.16.0
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-25296
PYSEC-2026-1504
GHSA-wpq5-3366-mqw4
Jul 07, 2026
Label Studio allows Cross-Site Scripting (XSS) via GET request to `/projects/upload-example` endpoint
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
DescriptionLabel Studio's The vulnerability exists because the upload-example endpoint renders user-provided HTML content without proper sanitization on a GET request. This allows attackers to inject and execute arbitrary JavaScript in victims' browsers by getting them to visit a maliciously crafted URL. This is considered vulnerable because it enables attackers to execute JavaScript in victims' contexts, potentially allowing theft of sensitive data, session hijacking, or other malicious actions. Steps to reproduce
When executed, the payload causes the application to render an HTML page containing an img tag that fails to load, triggering the onerror event handler which executes base64-decoded JavaScript, demonstrating successful XSS execution in the victim's browser. Mitigations
ImpactThe vulnerability requires no special privileges and can be exploited by getting a victim to visit a crafted URL. The impact is high as it allows arbitrary JavaScript execution in victims' browsers, potentially exposing sensitive data or enabling account takeover through session theft. Affected versions
0.4.1
0.4.2
0.4.3
0.4.4
0.4.4.post1
0.4.4.post2
0.4.5
0.4.6
0.4.6.post1
0.4.6.post2
0.4.7
0.4.8
+ 76 more Show less
0.5.0
0.5.1
0.6.0
0.6.1
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.4.post0
0.7.4.post1
0.7.5.post1
0.7.5.post2
0.8.0
0.8.0.post0
0.8.1
0.8.1.post0
0.8.2
0.8.2.post0
0.9.0
0.9.0.post2
0.9.0.post3
0.9.0.post4
0.9.0.post5
0.9.1
0.9.1.post0
0.9.1.post1
0.9.1.post2
1.0.0
1.0.0.post0
1.0.0.post1
1.0.0.post2
1.0.0.post3
1.0.1
1.0.2
1.0.2.post0
1.1.0
1.1.0rc0
1.1.1
1.10.0
1.10.0.post0
1.10.1
1.11.0
1.12.0
1.12.0.post0
1.12.1
1.13.0
1.13.1
1.14.0
1.14.0.post0
1.15.0
1.2
1.3
1.3.post0
1.3.post1
1.4
1.4.1
1.4.1.post0
1.4.1.post1
1.5.0
1.5.0.post0
1.6.0
1.7.0
1.7.1
1.7.2
1.7.3
1.8.0
1.8.1
1.8.2
1.8.2.post0
1.8.2.post1
1.9.0
1.9.1
1.9.1.post0
1.9.2
1.9.2.post0
Fixed in
1.16.0
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-47783
GHSA-8jhr-wpcm-hh4h
PYSEC-2025-124
May 15, 2025
label-studio vulnerable to Cross-Site Scripting (Reflected) via the label_config parameter.
High
Network
Low
None
SummaryThe vulnerability allows an attacker to inject a malicious script into the context of a web page, which can lead to data theft, unauthorized actions on behalf of the user, and other attacks. DetailsThe vulnerability is reproducible when sending a properly formatted request to the
The vulnerability is specifically located in line 57, where HttpResponse is used.
PoCSend the following request after changing the
Or you can create a vulnerable HTML page by changing
Impact
Affected versions
0.4.1
0.4.2
0.4.3
0.4.4
0.4.4.post1
0.4.4.post2
0.4.5
0.4.6
0.4.6.post1
0.4.6.post2
0.4.7
0.4.8
+ 78 more Show less
0.5.0
0.5.1
0.6.0
0.6.1
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.4.post0
0.7.4.post1
0.7.5.post1
0.7.5.post2
0.8.0
0.8.0.post0
0.8.1
0.8.1.post0
0.8.2
0.8.2.post0
0.9.0
0.9.0.post2
0.9.0.post3
0.9.0.post4
0.9.0.post5
0.9.1
0.9.1.post0
0.9.1.post1
0.9.1.post2
1.0.0
1.0.0.post0
1.0.0.post1
1.0.0.post2
1.0.0.post3
1.0.1
1.0.2
1.0.2.post0
1.1.0
1.1.0rc0
1.1.1
1.10.0
1.10.0.post0
1.10.1
1.11.0
1.12.0
1.12.0.post0
1.12.1
1.13.0
1.13.1
1.14.0
1.14.0.post0
1.15.0
1.16.0
1.17.0
1.2
1.3
1.3.post0
1.3.post1
1.4
1.4.1
1.4.1.post0
1.4.1.post1
1.5.0
1.5.0.post0
1.6.0
1.7.0
1.7.1
1.7.2
1.7.3
1.8.0
1.8.1
1.8.2
1.8.2.post0
1.8.2.post1
1.9.0
1.9.1
1.9.1.post0
1.9.2
1.9.2.post0
Fixed in
1.18.0
References
Updated Jun 06, 2026 · Source: OSV.dev | ||
1.12.1
patch
4 CVEs
CVE-2026-22033
PYSEC-2026-1502
GHSA-2mq9-hm29-8qch
Jul 07, 2026
Label Studio is vulnerable to full account takeover by chaining Stored XSS + IDOR in User Profile via custom_hotkeys field
Critical
Network
Low
Low
None
PrologueThese vulnerabilities have been found and chained by DCODX-AI. Validation of the exploit chain has been confirmed manually. SummaryA persistent stored cross-site scripting (XSS) vulnerability exists in the custom_hotkeys functionality of the application. An authenticated attacker (or one who can trick a user/administrator into updating their custom_hotkeys) can inject JavaScript code that executes in other users’ browsers when those users load any page using the DetailsWithin
Here, user.custom_hotkeys is run through json_dumps_ensure_ascii (in In
The serializer allows
When another user loads a page using templates/base.html (for example PoC
Example request
Example response
ImpactExploitation impact:
Who is impacted:
Affected versions
0.4.1
0.4.2
0.4.3
0.4.4
0.4.4.post1
0.4.4.post2
0.4.5
0.4.6
0.4.6.post1
0.4.6.post2
0.4.7
0.4.8
+ 83 more Show less
0.5.0
0.5.1
0.6.0
0.6.1
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.4.post0
0.7.4.post1
0.7.5.post1
0.7.5.post2
0.8.0
0.8.0.post0
0.8.1
0.8.1.post0
0.8.2
0.8.2.post0
0.9.0
0.9.0.post2
0.9.0.post3
0.9.0.post4
0.9.0.post5
0.9.1
0.9.1.post0
0.9.1.post1
0.9.1.post2
1.0.0
1.0.0.post0
1.0.0.post1
1.0.0.post2
1.0.0.post3
1.0.1
1.0.2
1.0.2.post0
1.1.0
1.1.0rc0
1.1.1
1.10.0
1.10.0.post0
1.10.1
1.11.0
1.12.0
1.12.0.post0
1.12.1
1.13.0
1.13.1
1.14.0
1.14.0.post0
1.15.0
1.16.0
1.17.0
1.18.0
1.19.0
1.2
1.20.0
1.21.0
1.22.0
1.3
1.3.post0
1.3.post1
1.4
1.4.1
1.4.1.post0
1.4.1.post1
1.5.0
1.5.0.post0
1.6.0
1.7.0
1.7.1
1.7.2
1.7.3
1.8.0
1.8.1
1.8.2
1.8.2.post0
1.8.2.post1
1.9.0
1.9.1
1.9.1.post0
1.9.2
1.9.2.post0
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-25297
PYSEC-2026-1503
GHSA-m238-fmcw-wh58
Jul 07, 2026
Label Studio allows Server-Side Request Forgery in the S3 Storage Endpoint
8.6
/ 10
High
Network
Low
None
None
Changed
High
None
None
DescriptionLabel Studio's S3 storage integration feature contains a Server-Side Request Forgery (SSRF) vulnerability in its endpoint configuration. When creating an S3 storage connection, the application allows users to specify a custom S3 endpoint URL via the s3_endpoint parameter. This endpoint URL is passed directly to the boto3 AWS SDK without proper validation or restrictions on the protocol or destination. The vulnerability allows an attacker to make the application send HTTP requests to arbitrary internal services by specifying them as the S3 endpoint. When the storage sync operation is triggered, the application attempts to make S3 API calls to the specified endpoint, effectively making HTTP requests to the target service and returning the response in error messages. This SSRF vulnerability enables attackers to bypass network segmentation and access internal services that should not be accessible from the external network. The vulnerability is particularly severe because error messages from failed requests contain the full response body, allowing data exfiltration from internal services. Steps to reproduce
The application will attempt to connect to the specified endpoint URL as if it were an S3 service. When the request fails due to invalid S3 API responses, the error message will contain the raw response from the internal service, allowing access to internal resources. Mitigations
ImpactThis vulnerability has high severity as it allows authenticated users to make requests to arbitrary internal services from the application server, potentially exposing sensitive internal resources and bypassing network segmentation. The inclusion of response data in error messages makes this particularly effective for data exfiltration. Affected versions
0.4.1
0.4.2
0.4.3
0.4.4
0.4.4.post1
0.4.4.post2
0.4.5
0.4.6
0.4.6.post1
0.4.6.post2
0.4.7
0.4.8
+ 76 more Show less
0.5.0
0.5.1
0.6.0
0.6.1
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.4.post0
0.7.4.post1
0.7.5.post1
0.7.5.post2
0.8.0
0.8.0.post0
0.8.1
0.8.1.post0
0.8.2
0.8.2.post0
0.9.0
0.9.0.post2
0.9.0.post3
0.9.0.post4
0.9.0.post5
0.9.1
0.9.1.post0
0.9.1.post1
0.9.1.post2
1.0.0
1.0.0.post0
1.0.0.post1
1.0.0.post2
1.0.0.post3
1.0.1
1.0.2
1.0.2.post0
1.1.0
1.1.0rc0
1.1.1
1.10.0
1.10.0.post0
1.10.1
1.11.0
1.12.0
1.12.0.post0
1.12.1
1.13.0
1.13.1
1.14.0
1.14.0.post0
1.15.0
1.2
1.3
1.3.post0
1.3.post1
1.4
1.4.1
1.4.1.post0
1.4.1.post1
1.5.0
1.5.0.post0
1.6.0
1.7.0
1.7.1
1.7.2
1.7.3
1.8.0
1.8.1
1.8.2
1.8.2.post0
1.8.2.post1
1.9.0
1.9.1
1.9.1.post0
1.9.2
1.9.2.post0
Fixed in
1.16.0
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-25296
PYSEC-2026-1504
GHSA-wpq5-3366-mqw4
Jul 07, 2026
Label Studio allows Cross-Site Scripting (XSS) via GET request to `/projects/upload-example` endpoint
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
DescriptionLabel Studio's The vulnerability exists because the upload-example endpoint renders user-provided HTML content without proper sanitization on a GET request. This allows attackers to inject and execute arbitrary JavaScript in victims' browsers by getting them to visit a maliciously crafted URL. This is considered vulnerable because it enables attackers to execute JavaScript in victims' contexts, potentially allowing theft of sensitive data, session hijacking, or other malicious actions. Steps to reproduce
When executed, the payload causes the application to render an HTML page containing an img tag that fails to load, triggering the onerror event handler which executes base64-decoded JavaScript, demonstrating successful XSS execution in the victim's browser. Mitigations
ImpactThe vulnerability requires no special privileges and can be exploited by getting a victim to visit a crafted URL. The impact is high as it allows arbitrary JavaScript execution in victims' browsers, potentially exposing sensitive data or enabling account takeover through session theft. Affected versions
0.4.1
0.4.2
0.4.3
0.4.4
0.4.4.post1
0.4.4.post2
0.4.5
0.4.6
0.4.6.post1
0.4.6.post2
0.4.7
0.4.8
+ 76 more Show less
0.5.0
0.5.1
0.6.0
0.6.1
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.4.post0
0.7.4.post1
0.7.5.post1
0.7.5.post2
0.8.0
0.8.0.post0
0.8.1
0.8.1.post0
0.8.2
0.8.2.post0
0.9.0
0.9.0.post2
0.9.0.post3
0.9.0.post4
0.9.0.post5
0.9.1
0.9.1.post0
0.9.1.post1
0.9.1.post2
1.0.0
1.0.0.post0
1.0.0.post1
1.0.0.post2
1.0.0.post3
1.0.1
1.0.2
1.0.2.post0
1.1.0
1.1.0rc0
1.1.1
1.10.0
1.10.0.post0
1.10.1
1.11.0
1.12.0
1.12.0.post0
1.12.1
1.13.0
1.13.1
1.14.0
1.14.0.post0
1.15.0
1.2
1.3
1.3.post0
1.3.post1
1.4
1.4.1
1.4.1.post0
1.4.1.post1
1.5.0
1.5.0.post0
1.6.0
1.7.0
1.7.1
1.7.2
1.7.3
1.8.0
1.8.1
1.8.2
1.8.2.post0
1.8.2.post1
1.9.0
1.9.1
1.9.1.post0
1.9.2
1.9.2.post0
Fixed in
1.16.0
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-47783
GHSA-8jhr-wpcm-hh4h
PYSEC-2025-124
May 15, 2025
label-studio vulnerable to Cross-Site Scripting (Reflected) via the label_config parameter.
High
Network
Low
None
SummaryThe vulnerability allows an attacker to inject a malicious script into the context of a web page, which can lead to data theft, unauthorized actions on behalf of the user, and other attacks. DetailsThe vulnerability is reproducible when sending a properly formatted request to the
The vulnerability is specifically located in line 57, where HttpResponse is used.
PoCSend the following request after changing the
Or you can create a vulnerable HTML page by changing
Impact
Affected versions
0.4.1
0.4.2
0.4.3
0.4.4
0.4.4.post1
0.4.4.post2
0.4.5
0.4.6
0.4.6.post1
0.4.6.post2
0.4.7
0.4.8
+ 78 more Show less
0.5.0
0.5.1
0.6.0
0.6.1
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.4.post0
0.7.4.post1
0.7.5.post1
0.7.5.post2
0.8.0
0.8.0.post0
0.8.1
0.8.1.post0
0.8.2
0.8.2.post0
0.9.0
0.9.0.post2
0.9.0.post3
0.9.0.post4
0.9.0.post5
0.9.1
0.9.1.post0
0.9.1.post1
0.9.1.post2
1.0.0
1.0.0.post0
1.0.0.post1
1.0.0.post2
1.0.0.post3
1.0.1
1.0.2
1.0.2.post0
1.1.0
1.1.0rc0
1.1.1
1.10.0
1.10.0.post0
1.10.1
1.11.0
1.12.0
1.12.0.post0
1.12.1
1.13.0
1.13.1
1.14.0
1.14.0.post0
1.15.0
1.16.0
1.17.0
1.2
1.3
1.3.post0
1.3.post1
1.4
1.4.1
1.4.1.post0
1.4.1.post1
1.5.0
1.5.0.post0
1.6.0
1.7.0
1.7.1
1.7.2
1.7.3
1.8.0
1.8.1
1.8.2
1.8.2.post0
1.8.2.post1
1.9.0
1.9.1
1.9.1.post0
1.9.2
1.9.2.post0
Fixed in
1.18.0
References
Updated Jun 06, 2026 · Source: OSV.dev | ||
1.12.0.post0
pre
4 CVEs
CVE-2026-22033
PYSEC-2026-1502
GHSA-2mq9-hm29-8qch
Jul 07, 2026
Label Studio is vulnerable to full account takeover by chaining Stored XSS + IDOR in User Profile via custom_hotkeys field
Critical
Network
Low
Low
None
PrologueThese vulnerabilities have been found and chained by DCODX-AI. Validation of the exploit chain has been confirmed manually. SummaryA persistent stored cross-site scripting (XSS) vulnerability exists in the custom_hotkeys functionality of the application. An authenticated attacker (or one who can trick a user/administrator into updating their custom_hotkeys) can inject JavaScript code that executes in other users’ browsers when those users load any page using the DetailsWithin
Here, user.custom_hotkeys is run through json_dumps_ensure_ascii (in In
The serializer allows
When another user loads a page using templates/base.html (for example PoC
Example request
Example response
ImpactExploitation impact:
Who is impacted:
Affected versions
0.4.1
0.4.2
0.4.3
0.4.4
0.4.4.post1
0.4.4.post2
0.4.5
0.4.6
0.4.6.post1
0.4.6.post2
0.4.7
0.4.8
+ 83 more Show less
0.5.0
0.5.1
0.6.0
0.6.1
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.4.post0
0.7.4.post1
0.7.5.post1
0.7.5.post2
0.8.0
0.8.0.post0
0.8.1
0.8.1.post0
0.8.2
0.8.2.post0
0.9.0
0.9.0.post2
0.9.0.post3
0.9.0.post4
0.9.0.post5
0.9.1
0.9.1.post0
0.9.1.post1
0.9.1.post2
1.0.0
1.0.0.post0
1.0.0.post1
1.0.0.post2
1.0.0.post3
1.0.1
1.0.2
1.0.2.post0
1.1.0
1.1.0rc0
1.1.1
1.10.0
1.10.0.post0
1.10.1
1.11.0
1.12.0
1.12.0.post0
1.12.1
1.13.0
1.13.1
1.14.0
1.14.0.post0
1.15.0
1.16.0
1.17.0
1.18.0
1.19.0
1.2
1.20.0
1.21.0
1.22.0
1.3
1.3.post0
1.3.post1
1.4
1.4.1
1.4.1.post0
1.4.1.post1
1.5.0
1.5.0.post0
1.6.0
1.7.0
1.7.1
1.7.2
1.7.3
1.8.0
1.8.1
1.8.2
1.8.2.post0
1.8.2.post1
1.9.0
1.9.1
1.9.1.post0
1.9.2
1.9.2.post0
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-25297
PYSEC-2026-1503
GHSA-m238-fmcw-wh58
Jul 07, 2026
Label Studio allows Server-Side Request Forgery in the S3 Storage Endpoint
8.6
/ 10
High
Network
Low
None
None
Changed
High
None
None
DescriptionLabel Studio's S3 storage integration feature contains a Server-Side Request Forgery (SSRF) vulnerability in its endpoint configuration. When creating an S3 storage connection, the application allows users to specify a custom S3 endpoint URL via the s3_endpoint parameter. This endpoint URL is passed directly to the boto3 AWS SDK without proper validation or restrictions on the protocol or destination. The vulnerability allows an attacker to make the application send HTTP requests to arbitrary internal services by specifying them as the S3 endpoint. When the storage sync operation is triggered, the application attempts to make S3 API calls to the specified endpoint, effectively making HTTP requests to the target service and returning the response in error messages. This SSRF vulnerability enables attackers to bypass network segmentation and access internal services that should not be accessible from the external network. The vulnerability is particularly severe because error messages from failed requests contain the full response body, allowing data exfiltration from internal services. Steps to reproduce
The application will attempt to connect to the specified endpoint URL as if it were an S3 service. When the request fails due to invalid S3 API responses, the error message will contain the raw response from the internal service, allowing access to internal resources. Mitigations
ImpactThis vulnerability has high severity as it allows authenticated users to make requests to arbitrary internal services from the application server, potentially exposing sensitive internal resources and bypassing network segmentation. The inclusion of response data in error messages makes this particularly effective for data exfiltration. Affected versions
0.4.1
0.4.2
0.4.3
0.4.4
0.4.4.post1
0.4.4.post2
0.4.5
0.4.6
0.4.6.post1
0.4.6.post2
0.4.7
0.4.8
+ 76 more Show less
0.5.0
0.5.1
0.6.0
0.6.1
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.4.post0
0.7.4.post1
0.7.5.post1
0.7.5.post2
0.8.0
0.8.0.post0
0.8.1
0.8.1.post0
0.8.2
0.8.2.post0
0.9.0
0.9.0.post2
0.9.0.post3
0.9.0.post4
0.9.0.post5
0.9.1
0.9.1.post0
0.9.1.post1
0.9.1.post2
1.0.0
1.0.0.post0
1.0.0.post1
1.0.0.post2
1.0.0.post3
1.0.1
1.0.2
1.0.2.post0
1.1.0
1.1.0rc0
1.1.1
1.10.0
1.10.0.post0
1.10.1
1.11.0
1.12.0
1.12.0.post0
1.12.1
1.13.0
1.13.1
1.14.0
1.14.0.post0
1.15.0
1.2
1.3
1.3.post0
1.3.post1
1.4
1.4.1
1.4.1.post0
1.4.1.post1
1.5.0
1.5.0.post0
1.6.0
1.7.0
1.7.1
1.7.2
1.7.3
1.8.0
1.8.1
1.8.2
1.8.2.post0
1.8.2.post1
1.9.0
1.9.1
1.9.1.post0
1.9.2
1.9.2.post0
Fixed in
1.16.0
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-25296
PYSEC-2026-1504
GHSA-wpq5-3366-mqw4
Jul 07, 2026
Label Studio allows Cross-Site Scripting (XSS) via GET request to `/projects/upload-example` endpoint
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
DescriptionLabel Studio's The vulnerability exists because the upload-example endpoint renders user-provided HTML content without proper sanitization on a GET request. This allows attackers to inject and execute arbitrary JavaScript in victims' browsers by getting them to visit a maliciously crafted URL. This is considered vulnerable because it enables attackers to execute JavaScript in victims' contexts, potentially allowing theft of sensitive data, session hijacking, or other malicious actions. Steps to reproduce
When executed, the payload causes the application to render an HTML page containing an img tag that fails to load, triggering the onerror event handler which executes base64-decoded JavaScript, demonstrating successful XSS execution in the victim's browser. Mitigations
ImpactThe vulnerability requires no special privileges and can be exploited by getting a victim to visit a crafted URL. The impact is high as it allows arbitrary JavaScript execution in victims' browsers, potentially exposing sensitive data or enabling account takeover through session theft. Affected versions
0.4.1
0.4.2
0.4.3
0.4.4
0.4.4.post1
0.4.4.post2
0.4.5
0.4.6
0.4.6.post1
0.4.6.post2
0.4.7
0.4.8
+ 76 more Show less
0.5.0
0.5.1
0.6.0
0.6.1
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.4.post0
0.7.4.post1
0.7.5.post1
0.7.5.post2
0.8.0
0.8.0.post0
0.8.1
0.8.1.post0
0.8.2
0.8.2.post0
0.9.0
0.9.0.post2
0.9.0.post3
0.9.0.post4
0.9.0.post5
0.9.1
0.9.1.post0
0.9.1.post1
0.9.1.post2
1.0.0
1.0.0.post0
1.0.0.post1
1.0.0.post2
1.0.0.post3
1.0.1
1.0.2
1.0.2.post0
1.1.0
1.1.0rc0
1.1.1
1.10.0
1.10.0.post0
1.10.1
1.11.0
1.12.0
1.12.0.post0
1.12.1
1.13.0
1.13.1
1.14.0
1.14.0.post0
1.15.0
1.2
1.3
1.3.post0
1.3.post1
1.4
1.4.1
1.4.1.post0
1.4.1.post1
1.5.0
1.5.0.post0
1.6.0
1.7.0
1.7.1
1.7.2
1.7.3
1.8.0
1.8.1
1.8.2
1.8.2.post0
1.8.2.post1
1.9.0
1.9.1
1.9.1.post0
1.9.2
1.9.2.post0
Fixed in
1.16.0
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-47783
GHSA-8jhr-wpcm-hh4h
PYSEC-2025-124
May 15, 2025
label-studio vulnerable to Cross-Site Scripting (Reflected) via the label_config parameter.
High
Network
Low
None
SummaryThe vulnerability allows an attacker to inject a malicious script into the context of a web page, which can lead to data theft, unauthorized actions on behalf of the user, and other attacks. DetailsThe vulnerability is reproducible when sending a properly formatted request to the
The vulnerability is specifically located in line 57, where HttpResponse is used.
PoCSend the following request after changing the
Or you can create a vulnerable HTML page by changing
Impact
Affected versions
0.4.1
0.4.2
0.4.3
0.4.4
0.4.4.post1
0.4.4.post2
0.4.5
0.4.6
0.4.6.post1
0.4.6.post2
0.4.7
0.4.8
+ 78 more Show less
0.5.0
0.5.1
0.6.0
0.6.1
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.4.post0
0.7.4.post1
0.7.5.post1
0.7.5.post2
0.8.0
0.8.0.post0
0.8.1
0.8.1.post0
0.8.2
0.8.2.post0
0.9.0
0.9.0.post2
0.9.0.post3
0.9.0.post4
0.9.0.post5
0.9.1
0.9.1.post0
0.9.1.post1
0.9.1.post2
1.0.0
1.0.0.post0
1.0.0.post1
1.0.0.post2
1.0.0.post3
1.0.1
1.0.2
1.0.2.post0
1.1.0
1.1.0rc0
1.1.1
1.10.0
1.10.0.post0
1.10.1
1.11.0
1.12.0
1.12.0.post0
1.12.1
1.13.0
1.13.1
1.14.0
1.14.0.post0
1.15.0
1.16.0
1.17.0
1.2
1.3
1.3.post0
1.3.post1
1.4
1.4.1
1.4.1.post0
1.4.1.post1
1.5.0
1.5.0.post0
1.6.0
1.7.0
1.7.1
1.7.2
1.7.3
1.8.0
1.8.1
1.8.2
1.8.2.post0
1.8.2.post1
1.9.0
1.9.1
1.9.1.post0
1.9.2
1.9.2.post0
Fixed in
1.18.0
References
Updated Jun 06, 2026 · Source: OSV.dev | ||
1.12.0
minor
4 CVEs
CVE-2026-22033
PYSEC-2026-1502
GHSA-2mq9-hm29-8qch
Jul 07, 2026
Label Studio is vulnerable to full account takeover by chaining Stored XSS + IDOR in User Profile via custom_hotkeys field
Critical
Network
Low
Low
None
PrologueThese vulnerabilities have been found and chained by DCODX-AI. Validation of the exploit chain has been confirmed manually. SummaryA persistent stored cross-site scripting (XSS) vulnerability exists in the custom_hotkeys functionality of the application. An authenticated attacker (or one who can trick a user/administrator into updating their custom_hotkeys) can inject JavaScript code that executes in other users’ browsers when those users load any page using the DetailsWithin
Here, user.custom_hotkeys is run through json_dumps_ensure_ascii (in In
The serializer allows
When another user loads a page using templates/base.html (for example PoC
Example request
Example response
ImpactExploitation impact:
Who is impacted:
Affected versions
0.4.1
0.4.2
0.4.3
0.4.4
0.4.4.post1
0.4.4.post2
0.4.5
0.4.6
0.4.6.post1
0.4.6.post2
0.4.7
0.4.8
+ 83 more Show less
0.5.0
0.5.1
0.6.0
0.6.1
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.4.post0
0.7.4.post1
0.7.5.post1
0.7.5.post2
0.8.0
0.8.0.post0
0.8.1
0.8.1.post0
0.8.2
0.8.2.post0
0.9.0
0.9.0.post2
0.9.0.post3
0.9.0.post4
0.9.0.post5
0.9.1
0.9.1.post0
0.9.1.post1
0.9.1.post2
1.0.0
1.0.0.post0
1.0.0.post1
1.0.0.post2
1.0.0.post3
1.0.1
1.0.2
1.0.2.post0
1.1.0
1.1.0rc0
1.1.1
1.10.0
1.10.0.post0
1.10.1
1.11.0
1.12.0
1.12.0.post0
1.12.1
1.13.0
1.13.1
1.14.0
1.14.0.post0
1.15.0
1.16.0
1.17.0
1.18.0
1.19.0
1.2
1.20.0
1.21.0
1.22.0
1.3
1.3.post0
1.3.post1
1.4
1.4.1
1.4.1.post0
1.4.1.post1
1.5.0
1.5.0.post0
1.6.0
1.7.0
1.7.1
1.7.2
1.7.3
1.8.0
1.8.1
1.8.2
1.8.2.post0
1.8.2.post1
1.9.0
1.9.1
1.9.1.post0
1.9.2
1.9.2.post0
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-25297
PYSEC-2026-1503
GHSA-m238-fmcw-wh58
Jul 07, 2026
Label Studio allows Server-Side Request Forgery in the S3 Storage Endpoint
8.6
/ 10
High
Network
Low
None
None
Changed
High
None
None
DescriptionLabel Studio's S3 storage integration feature contains a Server-Side Request Forgery (SSRF) vulnerability in its endpoint configuration. When creating an S3 storage connection, the application allows users to specify a custom S3 endpoint URL via the s3_endpoint parameter. This endpoint URL is passed directly to the boto3 AWS SDK without proper validation or restrictions on the protocol or destination. The vulnerability allows an attacker to make the application send HTTP requests to arbitrary internal services by specifying them as the S3 endpoint. When the storage sync operation is triggered, the application attempts to make S3 API calls to the specified endpoint, effectively making HTTP requests to the target service and returning the response in error messages. This SSRF vulnerability enables attackers to bypass network segmentation and access internal services that should not be accessible from the external network. The vulnerability is particularly severe because error messages from failed requests contain the full response body, allowing data exfiltration from internal services. Steps to reproduce
The application will attempt to connect to the specified endpoint URL as if it were an S3 service. When the request fails due to invalid S3 API responses, the error message will contain the raw response from the internal service, allowing access to internal resources. Mitigations
ImpactThis vulnerability has high severity as it allows authenticated users to make requests to arbitrary internal services from the application server, potentially exposing sensitive internal resources and bypassing network segmentation. The inclusion of response data in error messages makes this particularly effective for data exfiltration. Affected versions
0.4.1
0.4.2
0.4.3
0.4.4
0.4.4.post1
0.4.4.post2
0.4.5
0.4.6
0.4.6.post1
0.4.6.post2
0.4.7
0.4.8
+ 76 more Show less
0.5.0
0.5.1
0.6.0
0.6.1
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.4.post0
0.7.4.post1
0.7.5.post1
0.7.5.post2
0.8.0
0.8.0.post0
0.8.1
0.8.1.post0
0.8.2
0.8.2.post0
0.9.0
0.9.0.post2
0.9.0.post3
0.9.0.post4
0.9.0.post5
0.9.1
0.9.1.post0
0.9.1.post1
0.9.1.post2
1.0.0
1.0.0.post0
1.0.0.post1
1.0.0.post2
1.0.0.post3
1.0.1
1.0.2
1.0.2.post0
1.1.0
1.1.0rc0
1.1.1
1.10.0
1.10.0.post0
1.10.1
1.11.0
1.12.0
1.12.0.post0
1.12.1
1.13.0
1.13.1
1.14.0
1.14.0.post0
1.15.0
1.2
1.3
1.3.post0
1.3.post1
1.4
1.4.1
1.4.1.post0
1.4.1.post1
1.5.0
1.5.0.post0
1.6.0
1.7.0
1.7.1
1.7.2
1.7.3
1.8.0
1.8.1
1.8.2
1.8.2.post0
1.8.2.post1
1.9.0
1.9.1
1.9.1.post0
1.9.2
1.9.2.post0
Fixed in
1.16.0
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-25296
PYSEC-2026-1504
GHSA-wpq5-3366-mqw4
Jul 07, 2026
Label Studio allows Cross-Site Scripting (XSS) via GET request to `/projects/upload-example` endpoint
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
DescriptionLabel Studio's The vulnerability exists because the upload-example endpoint renders user-provided HTML content without proper sanitization on a GET request. This allows attackers to inject and execute arbitrary JavaScript in victims' browsers by getting them to visit a maliciously crafted URL. This is considered vulnerable because it enables attackers to execute JavaScript in victims' contexts, potentially allowing theft of sensitive data, session hijacking, or other malicious actions. Steps to reproduce
When executed, the payload causes the application to render an HTML page containing an img tag that fails to load, triggering the onerror event handler which executes base64-decoded JavaScript, demonstrating successful XSS execution in the victim's browser. Mitigations
ImpactThe vulnerability requires no special privileges and can be exploited by getting a victim to visit a crafted URL. The impact is high as it allows arbitrary JavaScript execution in victims' browsers, potentially exposing sensitive data or enabling account takeover through session theft. Affected versions
0.4.1
0.4.2
0.4.3
0.4.4
0.4.4.post1
0.4.4.post2
0.4.5
0.4.6
0.4.6.post1
0.4.6.post2
0.4.7
0.4.8
+ 76 more Show less
0.5.0
0.5.1
0.6.0
0.6.1
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.4.post0
0.7.4.post1
0.7.5.post1
0.7.5.post2
0.8.0
0.8.0.post0
0.8.1
0.8.1.post0
0.8.2
0.8.2.post0
0.9.0
0.9.0.post2
0.9.0.post3
0.9.0.post4
0.9.0.post5
0.9.1
0.9.1.post0
0.9.1.post1
0.9.1.post2
1.0.0
1.0.0.post0
1.0.0.post1
1.0.0.post2
1.0.0.post3
1.0.1
1.0.2
1.0.2.post0
1.1.0
1.1.0rc0
1.1.1
1.10.0
1.10.0.post0
1.10.1
1.11.0
1.12.0
1.12.0.post0
1.12.1
1.13.0
1.13.1
1.14.0
1.14.0.post0
1.15.0
1.2
1.3
1.3.post0
1.3.post1
1.4
1.4.1
1.4.1.post0
1.4.1.post1
1.5.0
1.5.0.post0
1.6.0
1.7.0
1.7.1
1.7.2
1.7.3
1.8.0
1.8.1
1.8.2
1.8.2.post0
1.8.2.post1
1.9.0
1.9.1
1.9.1.post0
1.9.2
1.9.2.post0
Fixed in
1.16.0
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-47783
GHSA-8jhr-wpcm-hh4h
PYSEC-2025-124
May 15, 2025
label-studio vulnerable to Cross-Site Scripting (Reflected) via the label_config parameter.
High
Network
Low
None
SummaryThe vulnerability allows an attacker to inject a malicious script into the context of a web page, which can lead to data theft, unauthorized actions on behalf of the user, and other attacks. DetailsThe vulnerability is reproducible when sending a properly formatted request to the
The vulnerability is specifically located in line 57, where HttpResponse is used.
PoCSend the following request after changing the
Or you can create a vulnerable HTML page by changing
Impact
Affected versions
0.4.1
0.4.2
0.4.3
0.4.4
0.4.4.post1
0.4.4.post2
0.4.5
0.4.6
0.4.6.post1
0.4.6.post2
0.4.7
0.4.8
+ 78 more Show less
0.5.0
0.5.1
0.6.0
0.6.1
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.4.post0
0.7.4.post1
0.7.5.post1
0.7.5.post2
0.8.0
0.8.0.post0
0.8.1
0.8.1.post0
0.8.2
0.8.2.post0
0.9.0
0.9.0.post2
0.9.0.post3
0.9.0.post4
0.9.0.post5
0.9.1
0.9.1.post0
0.9.1.post1
0.9.1.post2
1.0.0
1.0.0.post0
1.0.0.post1
1.0.0.post2
1.0.0.post3
1.0.1
1.0.2
1.0.2.post0
1.1.0
1.1.0rc0
1.1.1
1.10.0
1.10.0.post0
1.10.1
1.11.0
1.12.0
1.12.0.post0
1.12.1
1.13.0
1.13.1
1.14.0
1.14.0.post0
1.15.0
1.16.0
1.17.0
1.2
1.3
1.3.post0
1.3.post1
1.4
1.4.1
1.4.1.post0
1.4.1.post1
1.5.0
1.5.0.post0
1.6.0
1.7.0
1.7.1
1.7.2
1.7.3
1.8.0
1.8.1
1.8.2
1.8.2.post0
1.8.2.post1
1.9.0
1.9.1
1.9.1.post0
1.9.2
1.9.2.post0
Fixed in
1.18.0
References
Updated Jun 06, 2026 · Source: OSV.dev | ||
1.11.0
minor
4 CVEs
CVE-2026-22033
PYSEC-2026-1502
GHSA-2mq9-hm29-8qch
Jul 07, 2026
Label Studio is vulnerable to full account takeover by chaining Stored XSS + IDOR in User Profile via custom_hotkeys field
Critical
Network
Low
Low
None
PrologueThese vulnerabilities have been found and chained by DCODX-AI. Validation of the exploit chain has been confirmed manually. SummaryA persistent stored cross-site scripting (XSS) vulnerability exists in the custom_hotkeys functionality of the application. An authenticated attacker (or one who can trick a user/administrator into updating their custom_hotkeys) can inject JavaScript code that executes in other users’ browsers when those users load any page using the DetailsWithin
Here, user.custom_hotkeys is run through json_dumps_ensure_ascii (in In
The serializer allows
When another user loads a page using templates/base.html (for example PoC
Example request
Example response
ImpactExploitation impact:
Who is impacted:
Affected versions
0.4.1
0.4.2
0.4.3
0.4.4
0.4.4.post1
0.4.4.post2
0.4.5
0.4.6
0.4.6.post1
0.4.6.post2
0.4.7
0.4.8
+ 83 more Show less
0.5.0
0.5.1
0.6.0
0.6.1
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.4.post0
0.7.4.post1
0.7.5.post1
0.7.5.post2
0.8.0
0.8.0.post0
0.8.1
0.8.1.post0
0.8.2
0.8.2.post0
0.9.0
0.9.0.post2
0.9.0.post3
0.9.0.post4
0.9.0.post5
0.9.1
0.9.1.post0
0.9.1.post1
0.9.1.post2
1.0.0
1.0.0.post0
1.0.0.post1
1.0.0.post2
1.0.0.post3
1.0.1
1.0.2
1.0.2.post0
1.1.0
1.1.0rc0
1.1.1
1.10.0
1.10.0.post0
1.10.1
1.11.0
1.12.0
1.12.0.post0
1.12.1
1.13.0
1.13.1
1.14.0
1.14.0.post0
1.15.0
1.16.0
1.17.0
1.18.0
1.19.0
1.2
1.20.0
1.21.0
1.22.0
1.3
1.3.post0
1.3.post1
1.4
1.4.1
1.4.1.post0
1.4.1.post1
1.5.0
1.5.0.post0
1.6.0
1.7.0
1.7.1
1.7.2
1.7.3
1.8.0
1.8.1
1.8.2
1.8.2.post0
1.8.2.post1
1.9.0
1.9.1
1.9.1.post0
1.9.2
1.9.2.post0
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-25297
PYSEC-2026-1503
GHSA-m238-fmcw-wh58
Jul 07, 2026
Label Studio allows Server-Side Request Forgery in the S3 Storage Endpoint
8.6
/ 10
High
Network
Low
None
None
Changed
High
None
None
DescriptionLabel Studio's S3 storage integration feature contains a Server-Side Request Forgery (SSRF) vulnerability in its endpoint configuration. When creating an S3 storage connection, the application allows users to specify a custom S3 endpoint URL via the s3_endpoint parameter. This endpoint URL is passed directly to the boto3 AWS SDK without proper validation or restrictions on the protocol or destination. The vulnerability allows an attacker to make the application send HTTP requests to arbitrary internal services by specifying them as the S3 endpoint. When the storage sync operation is triggered, the application attempts to make S3 API calls to the specified endpoint, effectively making HTTP requests to the target service and returning the response in error messages. This SSRF vulnerability enables attackers to bypass network segmentation and access internal services that should not be accessible from the external network. The vulnerability is particularly severe because error messages from failed requests contain the full response body, allowing data exfiltration from internal services. Steps to reproduce
The application will attempt to connect to the specified endpoint URL as if it were an S3 service. When the request fails due to invalid S3 API responses, the error message will contain the raw response from the internal service, allowing access to internal resources. Mitigations
ImpactThis vulnerability has high severity as it allows authenticated users to make requests to arbitrary internal services from the application server, potentially exposing sensitive internal resources and bypassing network segmentation. The inclusion of response data in error messages makes this particularly effective for data exfiltration. Affected versions
0.4.1
0.4.2
0.4.3
0.4.4
0.4.4.post1
0.4.4.post2
0.4.5
0.4.6
0.4.6.post1
0.4.6.post2
0.4.7
0.4.8
+ 76 more Show less
0.5.0
0.5.1
0.6.0
0.6.1
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.4.post0
0.7.4.post1
0.7.5.post1
0.7.5.post2
0.8.0
0.8.0.post0
0.8.1
0.8.1.post0
0.8.2
0.8.2.post0
0.9.0
0.9.0.post2
0.9.0.post3
0.9.0.post4
0.9.0.post5
0.9.1
0.9.1.post0
0.9.1.post1
0.9.1.post2
1.0.0
1.0.0.post0
1.0.0.post1
1.0.0.post2
1.0.0.post3
1.0.1
1.0.2
1.0.2.post0
1.1.0
1.1.0rc0
1.1.1
1.10.0
1.10.0.post0
1.10.1
1.11.0
1.12.0
1.12.0.post0
1.12.1
1.13.0
1.13.1
1.14.0
1.14.0.post0
1.15.0
1.2
1.3
1.3.post0
1.3.post1
1.4
1.4.1
1.4.1.post0
1.4.1.post1
1.5.0
1.5.0.post0
1.6.0
1.7.0
1.7.1
1.7.2
1.7.3
1.8.0
1.8.1
1.8.2
1.8.2.post0
1.8.2.post1
1.9.0
1.9.1
1.9.1.post0
1.9.2
1.9.2.post0
Fixed in
1.16.0
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-25296
PYSEC-2026-1504
GHSA-wpq5-3366-mqw4
Jul 07, 2026
Label Studio allows Cross-Site Scripting (XSS) via GET request to `/projects/upload-example` endpoint
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
DescriptionLabel Studio's The vulnerability exists because the upload-example endpoint renders user-provided HTML content without proper sanitization on a GET request. This allows attackers to inject and execute arbitrary JavaScript in victims' browsers by getting them to visit a maliciously crafted URL. This is considered vulnerable because it enables attackers to execute JavaScript in victims' contexts, potentially allowing theft of sensitive data, session hijacking, or other malicious actions. Steps to reproduce
When executed, the payload causes the application to render an HTML page containing an img tag that fails to load, triggering the onerror event handler which executes base64-decoded JavaScript, demonstrating successful XSS execution in the victim's browser. Mitigations
ImpactThe vulnerability requires no special privileges and can be exploited by getting a victim to visit a crafted URL. The impact is high as it allows arbitrary JavaScript execution in victims' browsers, potentially exposing sensitive data or enabling account takeover through session theft. Affected versions
0.4.1
0.4.2
0.4.3
0.4.4
0.4.4.post1
0.4.4.post2
0.4.5
0.4.6
0.4.6.post1
0.4.6.post2
0.4.7
0.4.8
+ 76 more Show less
0.5.0
0.5.1
0.6.0
0.6.1
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.4.post0
0.7.4.post1
0.7.5.post1
0.7.5.post2
0.8.0
0.8.0.post0
0.8.1
0.8.1.post0
0.8.2
0.8.2.post0
0.9.0
0.9.0.post2
0.9.0.post3
0.9.0.post4
0.9.0.post5
0.9.1
0.9.1.post0
0.9.1.post1
0.9.1.post2
1.0.0
1.0.0.post0
1.0.0.post1
1.0.0.post2
1.0.0.post3
1.0.1
1.0.2
1.0.2.post0
1.1.0
1.1.0rc0
1.1.1
1.10.0
1.10.0.post0
1.10.1
1.11.0
1.12.0
1.12.0.post0
1.12.1
1.13.0
1.13.1
1.14.0
1.14.0.post0
1.15.0
1.2
1.3
1.3.post0
1.3.post1
1.4
1.4.1
1.4.1.post0
1.4.1.post1
1.5.0
1.5.0.post0
1.6.0
1.7.0
1.7.1
1.7.2
1.7.3
1.8.0
1.8.1
1.8.2
1.8.2.post0
1.8.2.post1
1.9.0
1.9.1
1.9.1.post0
1.9.2
1.9.2.post0
Fixed in
1.16.0
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-47783
GHSA-8jhr-wpcm-hh4h
PYSEC-2025-124
May 15, 2025
label-studio vulnerable to Cross-Site Scripting (Reflected) via the label_config parameter.
High
Network
Low
None
SummaryThe vulnerability allows an attacker to inject a malicious script into the context of a web page, which can lead to data theft, unauthorized actions on behalf of the user, and other attacks. DetailsThe vulnerability is reproducible when sending a properly formatted request to the
The vulnerability is specifically located in line 57, where HttpResponse is used.
PoCSend the following request after changing the
Or you can create a vulnerable HTML page by changing
Impact
Affected versions
0.4.1
0.4.2
0.4.3
0.4.4
0.4.4.post1
0.4.4.post2
0.4.5
0.4.6
0.4.6.post1
0.4.6.post2
0.4.7
0.4.8
+ 78 more Show less
0.5.0
0.5.1
0.6.0
0.6.1
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.4.post0
0.7.4.post1
0.7.5.post1
0.7.5.post2
0.8.0
0.8.0.post0
0.8.1
0.8.1.post0
0.8.2
0.8.2.post0
0.9.0
0.9.0.post2
0.9.0.post3
0.9.0.post4
0.9.0.post5
0.9.1
0.9.1.post0
0.9.1.post1
0.9.1.post2
1.0.0
1.0.0.post0
1.0.0.post1
1.0.0.post2
1.0.0.post3
1.0.1
1.0.2
1.0.2.post0
1.1.0
1.1.0rc0
1.1.1
1.10.0
1.10.0.post0
1.10.1
1.11.0
1.12.0
1.12.0.post0
1.12.1
1.13.0
1.13.1
1.14.0
1.14.0.post0
1.15.0
1.16.0
1.17.0
1.2
1.3
1.3.post0
1.3.post1
1.4
1.4.1
1.4.1.post0
1.4.1.post1
1.5.0
1.5.0.post0
1.6.0
1.7.0
1.7.1
1.7.2
1.7.3
1.8.0
1.8.1
1.8.2
1.8.2.post0
1.8.2.post1
1.9.0
1.9.1
1.9.1.post0
1.9.2
1.9.2.post0
Fixed in
1.18.0
References
Updated Jun 06, 2026 · Source: OSV.dev | ||
1.10.1
patch
6 CVEs
CVE-2026-22033
PYSEC-2026-1502
GHSA-2mq9-hm29-8qch
Jul 07, 2026
Label Studio is vulnerable to full account takeover by chaining Stored XSS + IDOR in User Profile via custom_hotkeys field
Critical
Network
Low
Low
None
PrologueThese vulnerabilities have been found and chained by DCODX-AI. Validation of the exploit chain has been confirmed manually. SummaryA persistent stored cross-site scripting (XSS) vulnerability exists in the custom_hotkeys functionality of the application. An authenticated attacker (or one who can trick a user/administrator into updating their custom_hotkeys) can inject JavaScript code that executes in other users’ browsers when those users load any page using the DetailsWithin
Here, user.custom_hotkeys is run through json_dumps_ensure_ascii (in In
The serializer allows
When another user loads a page using templates/base.html (for example PoC
Example request
Example response
ImpactExploitation impact:
Who is impacted:
Affected versions
0.4.1
0.4.2
0.4.3
0.4.4
0.4.4.post1
0.4.4.post2
0.4.5
0.4.6
0.4.6.post1
0.4.6.post2
0.4.7
0.4.8
+ 83 more Show less
0.5.0
0.5.1
0.6.0
0.6.1
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.4.post0
0.7.4.post1
0.7.5.post1
0.7.5.post2
0.8.0
0.8.0.post0
0.8.1
0.8.1.post0
0.8.2
0.8.2.post0
0.9.0
0.9.0.post2
0.9.0.post3
0.9.0.post4
0.9.0.post5
0.9.1
0.9.1.post0
0.9.1.post1
0.9.1.post2
1.0.0
1.0.0.post0
1.0.0.post1
1.0.0.post2
1.0.0.post3
1.0.1
1.0.2
1.0.2.post0
1.1.0
1.1.0rc0
1.1.1
1.10.0
1.10.0.post0
1.10.1
1.11.0
1.12.0
1.12.0.post0
1.12.1
1.13.0
1.13.1
1.14.0
1.14.0.post0
1.15.0
1.16.0
1.17.0
1.18.0
1.19.0
1.2
1.20.0
1.21.0
1.22.0
1.3
1.3.post0
1.3.post1
1.4
1.4.1
1.4.1.post0
1.4.1.post1
1.5.0
1.5.0.post0
1.6.0
1.7.0
1.7.1
1.7.2
1.7.3
1.8.0
1.8.1
1.8.2
1.8.2.post0
1.8.2.post1
1.9.0
1.9.1
1.9.1.post0
1.9.2
1.9.2.post0
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-25297
PYSEC-2026-1503
GHSA-m238-fmcw-wh58
Jul 07, 2026
Label Studio allows Server-Side Request Forgery in the S3 Storage Endpoint
8.6
/ 10
High
Network
Low
None
None
Changed
High
None
None
DescriptionLabel Studio's S3 storage integration feature contains a Server-Side Request Forgery (SSRF) vulnerability in its endpoint configuration. When creating an S3 storage connection, the application allows users to specify a custom S3 endpoint URL via the s3_endpoint parameter. This endpoint URL is passed directly to the boto3 AWS SDK without proper validation or restrictions on the protocol or destination. The vulnerability allows an attacker to make the application send HTTP requests to arbitrary internal services by specifying them as the S3 endpoint. When the storage sync operation is triggered, the application attempts to make S3 API calls to the specified endpoint, effectively making HTTP requests to the target service and returning the response in error messages. This SSRF vulnerability enables attackers to bypass network segmentation and access internal services that should not be accessible from the external network. The vulnerability is particularly severe because error messages from failed requests contain the full response body, allowing data exfiltration from internal services. Steps to reproduce
The application will attempt to connect to the specified endpoint URL as if it were an S3 service. When the request fails due to invalid S3 API responses, the error message will contain the raw response from the internal service, allowing access to internal resources. Mitigations
ImpactThis vulnerability has high severity as it allows authenticated users to make requests to arbitrary internal services from the application server, potentially exposing sensitive internal resources and bypassing network segmentation. The inclusion of response data in error messages makes this particularly effective for data exfiltration. Affected versions
0.4.1
0.4.2
0.4.3
0.4.4
0.4.4.post1
0.4.4.post2
0.4.5
0.4.6
0.4.6.post1
0.4.6.post2
0.4.7
0.4.8
+ 76 more Show less
0.5.0
0.5.1
0.6.0
0.6.1
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.4.post0
0.7.4.post1
0.7.5.post1
0.7.5.post2
0.8.0
0.8.0.post0
0.8.1
0.8.1.post0
0.8.2
0.8.2.post0
0.9.0
0.9.0.post2
0.9.0.post3
0.9.0.post4
0.9.0.post5
0.9.1
0.9.1.post0
0.9.1.post1
0.9.1.post2
1.0.0
1.0.0.post0
1.0.0.post1
1.0.0.post2
1.0.0.post3
1.0.1
1.0.2
1.0.2.post0
1.1.0
1.1.0rc0
1.1.1
1.10.0
1.10.0.post0
1.10.1
1.11.0
1.12.0
1.12.0.post0
1.12.1
1.13.0
1.13.1
1.14.0
1.14.0.post0
1.15.0
1.2
1.3
1.3.post0
1.3.post1
1.4
1.4.1
1.4.1.post0
1.4.1.post1
1.5.0
1.5.0.post0
1.6.0
1.7.0
1.7.1
1.7.2
1.7.3
1.8.0
1.8.1
1.8.2
1.8.2.post0
1.8.2.post1
1.9.0
1.9.1
1.9.1.post0
1.9.2
1.9.2.post0
Fixed in
1.16.0
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-25296
PYSEC-2026-1504
GHSA-wpq5-3366-mqw4
Jul 07, 2026
Label Studio allows Cross-Site Scripting (XSS) via GET request to `/projects/upload-example` endpoint
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
DescriptionLabel Studio's The vulnerability exists because the upload-example endpoint renders user-provided HTML content without proper sanitization on a GET request. This allows attackers to inject and execute arbitrary JavaScript in victims' browsers by getting them to visit a maliciously crafted URL. This is considered vulnerable because it enables attackers to execute JavaScript in victims' contexts, potentially allowing theft of sensitive data, session hijacking, or other malicious actions. Steps to reproduce
When executed, the payload causes the application to render an HTML page containing an img tag that fails to load, triggering the onerror event handler which executes base64-decoded JavaScript, demonstrating successful XSS execution in the victim's browser. Mitigations
ImpactThe vulnerability requires no special privileges and can be exploited by getting a victim to visit a crafted URL. The impact is high as it allows arbitrary JavaScript execution in victims' browsers, potentially exposing sensitive data or enabling account takeover through session theft. Affected versions
0.4.1
0.4.2
0.4.3
0.4.4
0.4.4.post1
0.4.4.post2
0.4.5
0.4.6
0.4.6.post1
0.4.6.post2
0.4.7
0.4.8
+ 76 more Show less
0.5.0
0.5.1
0.6.0
0.6.1
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.4.post0
0.7.4.post1
0.7.5.post1
0.7.5.post2
0.8.0
0.8.0.post0
0.8.1
0.8.1.post0
0.8.2
0.8.2.post0
0.9.0
0.9.0.post2
0.9.0.post3
0.9.0.post4
0.9.0.post5
0.9.1
0.9.1.post0
0.9.1.post1
0.9.1.post2
1.0.0
1.0.0.post0
1.0.0.post1
1.0.0.post2
1.0.0.post3
1.0.1
1.0.2
1.0.2.post0
1.1.0
1.1.0rc0
1.1.1
1.10.0
1.10.0.post0
1.10.1
1.11.0
1.12.0
1.12.0.post0
1.12.1
1.13.0
1.13.1
1.14.0
1.14.0.post0
1.15.0
1.2
1.3
1.3.post0
1.3.post1
1.4
1.4.1
1.4.1.post0
1.4.1.post1
1.5.0
1.5.0.post0
1.6.0
1.7.0
1.7.1
1.7.2
1.7.3
1.8.0
1.8.1
1.8.2
1.8.2.post0
1.8.2.post1
1.9.0
1.9.1
1.9.1.post0
1.9.2
1.9.2.post0
Fixed in
1.16.0
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-47783
GHSA-8jhr-wpcm-hh4h
PYSEC-2025-124
May 15, 2025
label-studio vulnerable to Cross-Site Scripting (Reflected) via the label_config parameter.
High
Network
Low
None
SummaryThe vulnerability allows an attacker to inject a malicious script into the context of a web page, which can lead to data theft, unauthorized actions on behalf of the user, and other attacks. DetailsThe vulnerability is reproducible when sending a properly formatted request to the
The vulnerability is specifically located in line 57, where HttpResponse is used.
PoCSend the following request after changing the
Or you can create a vulnerable HTML page by changing
Impact
Affected versions
0.4.1
0.4.2
0.4.3
0.4.4
0.4.4.post1
0.4.4.post2
0.4.5
0.4.6
0.4.6.post1
0.4.6.post2
0.4.7
0.4.8
+ 78 more Show less
0.5.0
0.5.1
0.6.0
0.6.1
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.4.post0
0.7.4.post1
0.7.5.post1
0.7.5.post2
0.8.0
0.8.0.post0
0.8.1
0.8.1.post0
0.8.2
0.8.2.post0
0.9.0
0.9.0.post2
0.9.0.post3
0.9.0.post4
0.9.0.post5
0.9.1
0.9.1.post0
0.9.1.post1
0.9.1.post2
1.0.0
1.0.0.post0
1.0.0.post1
1.0.0.post2
1.0.0.post3
1.0.1
1.0.2
1.0.2.post0
1.1.0
1.1.0rc0
1.1.1
1.10.0
1.10.0.post0
1.10.1
1.11.0
1.12.0
1.12.0.post0
1.12.1
1.13.0
1.13.1
1.14.0
1.14.0.post0
1.15.0
1.16.0
1.17.0
1.2
1.3
1.3.post0
1.3.post1
1.4
1.4.1
1.4.1.post0
1.4.1.post1
1.5.0
1.5.0.post0
1.6.0
1.7.0
1.7.1
1.7.2
1.7.3
1.8.0
1.8.1
1.8.2
1.8.2.post0
1.8.2.post1
1.9.0
1.9.1
1.9.1.post0
1.9.2
1.9.2.post0
Fixed in
1.18.0
References
Updated Jun 06, 2026 · Source: OSV.dev
CVE-2024-26152
PYSEC-2024-249
GHSA-6xv9-957j-qfhg
Feb 22, 2024
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
SummaryOn all Label Studio versions prior to 1.11.0, data imported via file upload feature is not properly sanitized prior to being rendered within a DetailsNeed permission to use the "data import" function. This was reproduced on Label Studio 1.10.1. PoC
The following are the contents of the files used in the PoC
ImpactMalicious scripts can be injected into the code, and when linked with vulnerabilities such as CSRF, it can cause even greater damage. In particular, It can become a source of further attacks, especially when linked to social engineering. Affected versions
0.4.1
0.4.2
0.4.3
0.4.4
0.4.4.post1
0.4.4.post2
0.4.5
0.4.6
0.4.6.post1
0.4.6.post2
0.4.7
0.4.8
+ 113 more Show less
0.5.0
0.5.1
0.6.0
0.6.1
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.4.post0
0.7.4.post1
0.7.5.post1
0.7.5.post2
0.8.0
0.8.0.post0
0.8.1
0.8.1.post0
0.8.2
0.8.2.post0
0.9.0
0.9.0.post2
0.9.0.post3
0.9.0.post4
0.9.0.post5
0.9.1
0.9.1.post0
0.9.1.post1
0.9.1.post2
1.0.0
1.0.0.post0
1.0.0.post1
1.0.0.post2
1.0.0.post3
1.0.1
1.0.2
1.0.2.post0
1.1.0
1.1.0rc0
1.1.1
1.10.0
1.10.0.post0
1.10.1
1.2
1.3
1.3.post0
1.3.post1
1.4
1.4.1
1.4.1.post0
1.4.1.post1
1.5.0
1.5.0.post0
1.6.0
1.7.0
1.7.1
1.7.2
1.7.3
1.8.0
1.8.1
1.8.2
1.8.2.post0
1.8.2.post1
1.9.0
1.9.1
1.9.1.post0
1.9.2
1.9.2.post0
v1.4.1
v1.4.0
v1.3.0
v1.2.0
v1.1.1
v1.1.0
v1.0.2
v1.0.1
v1.0.0
v0.9.1.post1
v0.9.1.post0
v0.9.0.post5
v0.9.0.post4
v0.9.0.post3
v0.9.0
v0.8.2
v0.8.1
v0.8.0
v0.7.5.post0
v0.7.3
v0.7.2
v0.7.1
v0.7.0
v0.6.1
v0.6.0
v0.5.1
v0.4.8
v0.4.7
v0.4.6
v0.4.5
v0.4.4
v0.4.0
v0.3.0
v0.2.2
v.0.2.1-8
v.0.2.1-5
v.0.2.1-4
v.0.2.1-3
v.0.2.1-2
v.0.2.0
v.0.1.6
v.0.1.5
v.0.1.4
v.0.1.2
v.0.1.1
v.0.1.0
Fixed in
1.11.0
References
Updated Jun 10, 2026 · Source: OSV.dev
CVE-2023-47116
GHSA-p59w-9gqw-wj8r
PYSEC-2024-127
Jan 31, 2024
Label Studio SSRF on Import Bypassing `SSRF_PROTECTION_ENABLED` Protections
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
IntroductionThis write-up describes a vulnerability found in Label Studio, a popular open source data labeling tool. The vulnerability affects all versions of Label Studio prior to OverviewLabel Studio's SSRF protections that can be enabled by setting the DescriptionThe following
The
The issue here is the SSRF validation is only performed before the request is sent, and does not validate the destination IP address. Therefore, an attacker can either redirect the request or perform a DNS rebinding attack to bypass this protection. Proof of ConceptBoth the HTTP redirection and DNS rebinding methods for bypassing Label Studio's SSRF protections are explained below. HTTP RedirectionThe python
DNS Rebinding AttackDNS rebinding can bypass SSRF protections by resolving to an external IP address for the first resolution, but when the request is sent resolves to an internal IP address that is blocked. For an example, the domain ImpactSSRF vulnerabilities pose a significant risk on cloud environments, since instance credentials are managed by internal web APIs. An attacker can bypass Label Studio's SSRF protections to access internal web servers and partially compromise the confidentiality of those internal servers. Remediation Advice
Discovered
Affected versions
0.4.1
0.4.2
0.4.3
0.4.4
0.4.4.post1
0.4.4.post2
0.4.5
0.4.6
0.4.6.post1
0.4.6.post2
0.4.7
0.4.8
+ 67 more Show less
0.5.0
0.5.1
0.6.0
0.6.1
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.4.post0
0.7.4.post1
0.7.5.post1
0.7.5.post2
0.8.0
0.8.0.post0
0.8.1
0.8.1.post0
0.8.2
0.8.2.post0
0.9.0
0.9.0.post2
0.9.0.post3
0.9.0.post4
0.9.0.post5
0.9.1
0.9.1.post0
0.9.1.post1
0.9.1.post2
1.0.0
1.0.0.post0
1.0.0.post1
1.0.0.post2
1.0.0.post3
1.0.1
1.0.2
1.0.2.post0
1.1.0
1.1.0rc0
1.1.1
1.10.0
1.10.0.post0
1.10.1
1.2
1.3
1.3.post0
1.3.post1
1.4
1.4.1
1.4.1.post0
1.4.1.post1
1.5.0
1.5.0.post0
1.6.0
1.7.0
1.7.1
1.7.2
1.7.3
1.8.0
1.8.1
1.8.2
1.8.2.post0
1.8.2.post1
1.9.0
1.9.1
1.9.1.post0
1.9.2
1.9.2.post0
Fixed in
1.11.0
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
1.10.0.post0
pre
7 CVEs
CVE-2026-22033
PYSEC-2026-1502
GHSA-2mq9-hm29-8qch
Jul 07, 2026
Label Studio is vulnerable to full account takeover by chaining Stored XSS + IDOR in User Profile via custom_hotkeys field
Critical
Network
Low
Low
None
PrologueThese vulnerabilities have been found and chained by DCODX-AI. Validation of the exploit chain has been confirmed manually. SummaryA persistent stored cross-site scripting (XSS) vulnerability exists in the custom_hotkeys functionality of the application. An authenticated attacker (or one who can trick a user/administrator into updating their custom_hotkeys) can inject JavaScript code that executes in other users’ browsers when those users load any page using the DetailsWithin
Here, user.custom_hotkeys is run through json_dumps_ensure_ascii (in In
The serializer allows
When another user loads a page using templates/base.html (for example PoC
Example request
Example response
ImpactExploitation impact:
Who is impacted:
Affected versions
0.4.1
0.4.2
0.4.3
0.4.4
0.4.4.post1
0.4.4.post2
0.4.5
0.4.6
0.4.6.post1
0.4.6.post2
0.4.7
0.4.8
+ 83 more Show less
0.5.0
0.5.1
0.6.0
0.6.1
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.4.post0
0.7.4.post1
0.7.5.post1
0.7.5.post2
0.8.0
0.8.0.post0
0.8.1
0.8.1.post0
0.8.2
0.8.2.post0
0.9.0
0.9.0.post2
0.9.0.post3
0.9.0.post4
0.9.0.post5
0.9.1
0.9.1.post0
0.9.1.post1
0.9.1.post2
1.0.0
1.0.0.post0
1.0.0.post1
1.0.0.post2
1.0.0.post3
1.0.1
1.0.2
1.0.2.post0
1.1.0
1.1.0rc0
1.1.1
1.10.0
1.10.0.post0
1.10.1
1.11.0
1.12.0
1.12.0.post0
1.12.1
1.13.0
1.13.1
1.14.0
1.14.0.post0
1.15.0
1.16.0
1.17.0
1.18.0
1.19.0
1.2
1.20.0
1.21.0
1.22.0
1.3
1.3.post0
1.3.post1
1.4
1.4.1
1.4.1.post0
1.4.1.post1
1.5.0
1.5.0.post0
1.6.0
1.7.0
1.7.1
1.7.2
1.7.3
1.8.0
1.8.1
1.8.2
1.8.2.post0
1.8.2.post1
1.9.0
1.9.1
1.9.1.post0
1.9.2
1.9.2.post0
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-25297
PYSEC-2026-1503
GHSA-m238-fmcw-wh58
Jul 07, 2026
Label Studio allows Server-Side Request Forgery in the S3 Storage Endpoint
8.6
/ 10
High
Network
Low
None
None
Changed
High
None
None
DescriptionLabel Studio's S3 storage integration feature contains a Server-Side Request Forgery (SSRF) vulnerability in its endpoint configuration. When creating an S3 storage connection, the application allows users to specify a custom S3 endpoint URL via the s3_endpoint parameter. This endpoint URL is passed directly to the boto3 AWS SDK without proper validation or restrictions on the protocol or destination. The vulnerability allows an attacker to make the application send HTTP requests to arbitrary internal services by specifying them as the S3 endpoint. When the storage sync operation is triggered, the application attempts to make S3 API calls to the specified endpoint, effectively making HTTP requests to the target service and returning the response in error messages. This SSRF vulnerability enables attackers to bypass network segmentation and access internal services that should not be accessible from the external network. The vulnerability is particularly severe because error messages from failed requests contain the full response body, allowing data exfiltration from internal services. Steps to reproduce
The application will attempt to connect to the specified endpoint URL as if it were an S3 service. When the request fails due to invalid S3 API responses, the error message will contain the raw response from the internal service, allowing access to internal resources. Mitigations
ImpactThis vulnerability has high severity as it allows authenticated users to make requests to arbitrary internal services from the application server, potentially exposing sensitive internal resources and bypassing network segmentation. The inclusion of response data in error messages makes this particularly effective for data exfiltration. Affected versions
0.4.1
0.4.2
0.4.3
0.4.4
0.4.4.post1
0.4.4.post2
0.4.5
0.4.6
0.4.6.post1
0.4.6.post2
0.4.7
0.4.8
+ 76 more Show less
0.5.0
0.5.1
0.6.0
0.6.1
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.4.post0
0.7.4.post1
0.7.5.post1
0.7.5.post2
0.8.0
0.8.0.post0
0.8.1
0.8.1.post0
0.8.2
0.8.2.post0
0.9.0
0.9.0.post2
0.9.0.post3
0.9.0.post4
0.9.0.post5
0.9.1
0.9.1.post0
0.9.1.post1
0.9.1.post2
1.0.0
1.0.0.post0
1.0.0.post1
1.0.0.post2
1.0.0.post3
1.0.1
1.0.2
1.0.2.post0
1.1.0
1.1.0rc0
1.1.1
1.10.0
1.10.0.post0
1.10.1
1.11.0
1.12.0
1.12.0.post0
1.12.1
1.13.0
1.13.1
1.14.0
1.14.0.post0
1.15.0
1.2
1.3
1.3.post0
1.3.post1
1.4
1.4.1
1.4.1.post0
1.4.1.post1
1.5.0
1.5.0.post0
1.6.0
1.7.0
1.7.1
1.7.2
1.7.3
1.8.0
1.8.1
1.8.2
1.8.2.post0
1.8.2.post1
1.9.0
1.9.1
1.9.1.post0
1.9.2
1.9.2.post0
Fixed in
1.16.0
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-25296
PYSEC-2026-1504
GHSA-wpq5-3366-mqw4
Jul 07, 2026
Label Studio allows Cross-Site Scripting (XSS) via GET request to `/projects/upload-example` endpoint
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
DescriptionLabel Studio's The vulnerability exists because the upload-example endpoint renders user-provided HTML content without proper sanitization on a GET request. This allows attackers to inject and execute arbitrary JavaScript in victims' browsers by getting them to visit a maliciously crafted URL. This is considered vulnerable because it enables attackers to execute JavaScript in victims' contexts, potentially allowing theft of sensitive data, session hijacking, or other malicious actions. Steps to reproduce
When executed, the payload causes the application to render an HTML page containing an img tag that fails to load, triggering the onerror event handler which executes base64-decoded JavaScript, demonstrating successful XSS execution in the victim's browser. Mitigations
ImpactThe vulnerability requires no special privileges and can be exploited by getting a victim to visit a crafted URL. The impact is high as it allows arbitrary JavaScript execution in victims' browsers, potentially exposing sensitive data or enabling account takeover through session theft. Affected versions
0.4.1
0.4.2
0.4.3
0.4.4
0.4.4.post1
0.4.4.post2
0.4.5
0.4.6
0.4.6.post1
0.4.6.post2
0.4.7
0.4.8
+ 76 more Show less
0.5.0
0.5.1
0.6.0
0.6.1
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.4.post0
0.7.4.post1
0.7.5.post1
0.7.5.post2
0.8.0
0.8.0.post0
0.8.1
0.8.1.post0
0.8.2
0.8.2.post0
0.9.0
0.9.0.post2
0.9.0.post3
0.9.0.post4
0.9.0.post5
0.9.1
0.9.1.post0
0.9.1.post1
0.9.1.post2
1.0.0
1.0.0.post0
1.0.0.post1
1.0.0.post2
1.0.0.post3
1.0.1
1.0.2
1.0.2.post0
1.1.0
1.1.0rc0
1.1.1
1.10.0
1.10.0.post0
1.10.1
1.11.0
1.12.0
1.12.0.post0
1.12.1
1.13.0
1.13.1
1.14.0
1.14.0.post0
1.15.0
1.2
1.3
1.3.post0
1.3.post1
1.4
1.4.1
1.4.1.post0
1.4.1.post1
1.5.0
1.5.0.post0
1.6.0
1.7.0
1.7.1
1.7.2
1.7.3
1.8.0
1.8.1
1.8.2
1.8.2.post0
1.8.2.post1
1.9.0
1.9.1
1.9.1.post0
1.9.2
1.9.2.post0
Fixed in
1.16.0
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-47783
GHSA-8jhr-wpcm-hh4h
PYSEC-2025-124
May 15, 2025
label-studio vulnerable to Cross-Site Scripting (Reflected) via the label_config parameter.
High
Network
Low
None
SummaryThe vulnerability allows an attacker to inject a malicious script into the context of a web page, which can lead to data theft, unauthorized actions on behalf of the user, and other attacks. DetailsThe vulnerability is reproducible when sending a properly formatted request to the
The vulnerability is specifically located in line 57, where HttpResponse is used.
PoCSend the following request after changing the
Or you can create a vulnerable HTML page by changing
Impact
Affected versions
0.4.1
0.4.2
0.4.3
0.4.4
0.4.4.post1
0.4.4.post2
0.4.5
0.4.6
0.4.6.post1
0.4.6.post2
0.4.7
0.4.8
+ 78 more Show less
0.5.0
0.5.1
0.6.0
0.6.1
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.4.post0
0.7.4.post1
0.7.5.post1
0.7.5.post2
0.8.0
0.8.0.post0
0.8.1
0.8.1.post0
0.8.2
0.8.2.post0
0.9.0
0.9.0.post2
0.9.0.post3
0.9.0.post4
0.9.0.post5
0.9.1
0.9.1.post0
0.9.1.post1
0.9.1.post2
1.0.0
1.0.0.post0
1.0.0.post1
1.0.0.post2
1.0.0.post3
1.0.1
1.0.2
1.0.2.post0
1.1.0
1.1.0rc0
1.1.1
1.10.0
1.10.0.post0
1.10.1
1.11.0
1.12.0
1.12.0.post0
1.12.1
1.13.0
1.13.1
1.14.0
1.14.0.post0
1.15.0
1.16.0
1.17.0
1.2
1.3
1.3.post0
1.3.post1
1.4
1.4.1
1.4.1.post0
1.4.1.post1
1.5.0
1.5.0.post0
1.6.0
1.7.0
1.7.1
1.7.2
1.7.3
1.8.0
1.8.1
1.8.2
1.8.2.post0
1.8.2.post1
1.9.0
1.9.1
1.9.1.post0
1.9.2
1.9.2.post0
Fixed in
1.18.0
References
Updated Jun 06, 2026 · Source: OSV.dev
CVE-2024-26152
PYSEC-2024-249
GHSA-6xv9-957j-qfhg
Feb 22, 2024
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
SummaryOn all Label Studio versions prior to 1.11.0, data imported via file upload feature is not properly sanitized prior to being rendered within a DetailsNeed permission to use the "data import" function. This was reproduced on Label Studio 1.10.1. PoC
The following are the contents of the files used in the PoC
ImpactMalicious scripts can be injected into the code, and when linked with vulnerabilities such as CSRF, it can cause even greater damage. In particular, It can become a source of further attacks, especially when linked to social engineering. Affected versions
0.4.1
0.4.2
0.4.3
0.4.4
0.4.4.post1
0.4.4.post2
0.4.5
0.4.6
0.4.6.post1
0.4.6.post2
0.4.7
0.4.8
+ 113 more Show less
0.5.0
0.5.1
0.6.0
0.6.1
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.4.post0
0.7.4.post1
0.7.5.post1
0.7.5.post2
0.8.0
0.8.0.post0
0.8.1
0.8.1.post0
0.8.2
0.8.2.post0
0.9.0
0.9.0.post2
0.9.0.post3
0.9.0.post4
0.9.0.post5
0.9.1
0.9.1.post0
0.9.1.post1
0.9.1.post2
1.0.0
1.0.0.post0
1.0.0.post1
1.0.0.post2
1.0.0.post3
1.0.1
1.0.2
1.0.2.post0
1.1.0
1.1.0rc0
1.1.1
1.10.0
1.10.0.post0
1.10.1
1.2
1.3
1.3.post0
1.3.post1
1.4
1.4.1
1.4.1.post0
1.4.1.post1
1.5.0
1.5.0.post0
1.6.0
1.7.0
1.7.1
1.7.2
1.7.3
1.8.0
1.8.1
1.8.2
1.8.2.post0
1.8.2.post1
1.9.0
1.9.1
1.9.1.post0
1.9.2
1.9.2.post0
v1.4.1
v1.4.0
v1.3.0
v1.2.0
v1.1.1
v1.1.0
v1.0.2
v1.0.1
v1.0.0
v0.9.1.post1
v0.9.1.post0
v0.9.0.post5
v0.9.0.post4
v0.9.0.post3
v0.9.0
v0.8.2
v0.8.1
v0.8.0
v0.7.5.post0
v0.7.3
v0.7.2
v0.7.1
v0.7.0
v0.6.1
v0.6.0
v0.5.1
v0.4.8
v0.4.7
v0.4.6
v0.4.5
v0.4.4
v0.4.0
v0.3.0
v0.2.2
v.0.2.1-8
v.0.2.1-5
v.0.2.1-4
v.0.2.1-3
v.0.2.1-2
v.0.2.0
v.0.1.6
v.0.1.5
v.0.1.4
v.0.1.2
v.0.1.1
v.0.1.0
Fixed in
1.11.0
References
Updated Jun 10, 2026 · Source: OSV.dev
CVE-2023-47116
GHSA-p59w-9gqw-wj8r
PYSEC-2024-127
Jan 31, 2024
Label Studio SSRF on Import Bypassing `SSRF_PROTECTION_ENABLED` Protections
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
IntroductionThis write-up describes a vulnerability found in Label Studio, a popular open source data labeling tool. The vulnerability affects all versions of Label Studio prior to OverviewLabel Studio's SSRF protections that can be enabled by setting the DescriptionThe following
The
The issue here is the SSRF validation is only performed before the request is sent, and does not validate the destination IP address. Therefore, an attacker can either redirect the request or perform a DNS rebinding attack to bypass this protection. Proof of ConceptBoth the HTTP redirection and DNS rebinding methods for bypassing Label Studio's SSRF protections are explained below. HTTP RedirectionThe python
DNS Rebinding AttackDNS rebinding can bypass SSRF protections by resolving to an external IP address for the first resolution, but when the request is sent resolves to an internal IP address that is blocked. For an example, the domain ImpactSSRF vulnerabilities pose a significant risk on cloud environments, since instance credentials are managed by internal web APIs. An attacker can bypass Label Studio's SSRF protections to access internal web servers and partially compromise the confidentiality of those internal servers. Remediation Advice
Discovered
Affected versions
0.4.1
0.4.2
0.4.3
0.4.4
0.4.4.post1
0.4.4.post2
0.4.5
0.4.6
0.4.6.post1
0.4.6.post2
0.4.7
0.4.8
+ 67 more Show less
0.5.0
0.5.1
0.6.0
0.6.1
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.4.post0
0.7.4.post1
0.7.5.post1
0.7.5.post2
0.8.0
0.8.0.post0
0.8.1
0.8.1.post0
0.8.2
0.8.2.post0
0.9.0
0.9.0.post2
0.9.0.post3
0.9.0.post4
0.9.0.post5
0.9.1
0.9.1.post0
0.9.1.post1
0.9.1.post2
1.0.0
1.0.0.post0
1.0.0.post1
1.0.0.post2
1.0.0.post3
1.0.1
1.0.2
1.0.2.post0
1.1.0
1.1.0rc0
1.1.1
1.10.0
1.10.0.post0
1.10.1
1.2
1.3
1.3.post0
1.3.post1
1.4
1.4.1
1.4.1.post0
1.4.1.post1
1.5.0
1.5.0.post0
1.6.0
1.7.0
1.7.1
1.7.2
1.7.3
1.8.0
1.8.1
1.8.2
1.8.2.post0
1.8.2.post1
1.9.0
1.9.1
1.9.1.post0
1.9.2
1.9.2.post0
Fixed in
1.11.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-23633
GHSA-fq23-g58m-799r
PYSEC-2024-128
Jan 24, 2024
Cross-site Scripting Vulnerability on Data Import
4.7
/ 10
Medium
Network
Low
None
Required
Changed
Low
None
None
IntroductionThis write-up describes a vulnerability found in Label Studio, a popular open source data labeling tool. The vulnerability affects all versions of Label Studio prior to OverviewLabel Studio had a remote import feature allowed users to import data from a remote web source, that was downloaded and could be viewed on the website. This feature could had been abused to download a HTML file that executed malicious JavaScript code in the context of the Label Studio website. DescriptionThe following code snippet in Label Studio showed that is a URL passed the SSRF verification checks, the contents of the file would be downloaded using the filename in the URL.
The downloaded file path could then be retrieved by sending a request to
Since the Proof of ConceptBelow were the steps to recreate this issue:
ImpactExecuting arbitrary JavaScript could result in an attacker performing malicious actions on Label Studio users if they visit the crafted avatar image. For an example, an attacker can craft a JavaScript payload that adds a new Django Super Administrator user if a Django administrator visits the image. Remediation Advice
Discovered
Affected versions
0.4.1
0.4.2
0.4.3
0.4.4
0.4.4.post1
0.4.4.post2
0.4.5
0.4.6
0.4.6.post1
0.4.6.post2
0.4.7
0.4.8
+ 66 more Show less
0.5.0
0.5.1
0.6.0
0.6.1
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.4.post0
0.7.4.post1
0.7.5.post1
0.7.5.post2
0.8.0
0.8.0.post0
0.8.1
0.8.1.post0
0.8.2
0.8.2.post0
0.9.0
0.9.0.post2
0.9.0.post3
0.9.0.post4
0.9.0.post5
0.9.1
0.9.1.post0
0.9.1.post1
0.9.1.post2
1.0.0
1.0.0.post0
1.0.0.post1
1.0.0.post2
1.0.0.post3
1.0.1
1.0.2
1.0.2.post0
1.1.0
1.1.0rc0
1.1.1
1.10.0
1.10.0.post0
1.2
1.3
1.3.post0
1.3.post1
1.4
1.4.1
1.4.1.post0
1.4.1.post1
1.5.0
1.5.0.post0
1.6.0
1.7.0
1.7.1
1.7.2
1.7.3
1.8.0
1.8.1
1.8.2
1.8.2.post0
1.8.2.post1
1.9.0
1.9.1
1.9.1.post0
1.9.2
1.9.2.post0
Fixed in
1.10.1
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
1.10.0
minor
7 CVEs
CVE-2026-22033
PYSEC-2026-1502
GHSA-2mq9-hm29-8qch
Jul 07, 2026
Label Studio is vulnerable to full account takeover by chaining Stored XSS + IDOR in User Profile via custom_hotkeys field
Critical
Network
Low
Low
None
PrologueThese vulnerabilities have been found and chained by DCODX-AI. Validation of the exploit chain has been confirmed manually. SummaryA persistent stored cross-site scripting (XSS) vulnerability exists in the custom_hotkeys functionality of the application. An authenticated attacker (or one who can trick a user/administrator into updating their custom_hotkeys) can inject JavaScript code that executes in other users’ browsers when those users load any page using the DetailsWithin
Here, user.custom_hotkeys is run through json_dumps_ensure_ascii (in In
The serializer allows
When another user loads a page using templates/base.html (for example PoC
Example request
Example response
ImpactExploitation impact:
Who is impacted:
Affected versions
0.4.1
0.4.2
0.4.3
0.4.4
0.4.4.post1
0.4.4.post2
0.4.5
0.4.6
0.4.6.post1
0.4.6.post2
0.4.7
0.4.8
+ 83 more Show less
0.5.0
0.5.1
0.6.0
0.6.1
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.4.post0
0.7.4.post1
0.7.5.post1
0.7.5.post2
0.8.0
0.8.0.post0
0.8.1
0.8.1.post0
0.8.2
0.8.2.post0
0.9.0
0.9.0.post2
0.9.0.post3
0.9.0.post4
0.9.0.post5
0.9.1
0.9.1.post0
0.9.1.post1
0.9.1.post2
1.0.0
1.0.0.post0
1.0.0.post1
1.0.0.post2
1.0.0.post3
1.0.1
1.0.2
1.0.2.post0
1.1.0
1.1.0rc0
1.1.1
1.10.0
1.10.0.post0
1.10.1
1.11.0
1.12.0
1.12.0.post0
1.12.1
1.13.0
1.13.1
1.14.0
1.14.0.post0
1.15.0
1.16.0
1.17.0
1.18.0
1.19.0
1.2
1.20.0
1.21.0
1.22.0
1.3
1.3.post0
1.3.post1
1.4
1.4.1
1.4.1.post0
1.4.1.post1
1.5.0
1.5.0.post0
1.6.0
1.7.0
1.7.1
1.7.2
1.7.3
1.8.0
1.8.1
1.8.2
1.8.2.post0
1.8.2.post1
1.9.0
1.9.1
1.9.1.post0
1.9.2
1.9.2.post0
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-25297
PYSEC-2026-1503
GHSA-m238-fmcw-wh58
Jul 07, 2026
Label Studio allows Server-Side Request Forgery in the S3 Storage Endpoint
8.6
/ 10
High
Network
Low
None
None
Changed
High
None
None
DescriptionLabel Studio's S3 storage integration feature contains a Server-Side Request Forgery (SSRF) vulnerability in its endpoint configuration. When creating an S3 storage connection, the application allows users to specify a custom S3 endpoint URL via the s3_endpoint parameter. This endpoint URL is passed directly to the boto3 AWS SDK without proper validation or restrictions on the protocol or destination. The vulnerability allows an attacker to make the application send HTTP requests to arbitrary internal services by specifying them as the S3 endpoint. When the storage sync operation is triggered, the application attempts to make S3 API calls to the specified endpoint, effectively making HTTP requests to the target service and returning the response in error messages. This SSRF vulnerability enables attackers to bypass network segmentation and access internal services that should not be accessible from the external network. The vulnerability is particularly severe because error messages from failed requests contain the full response body, allowing data exfiltration from internal services. Steps to reproduce
The application will attempt to connect to the specified endpoint URL as if it were an S3 service. When the request fails due to invalid S3 API responses, the error message will contain the raw response from the internal service, allowing access to internal resources. Mitigations
ImpactThis vulnerability has high severity as it allows authenticated users to make requests to arbitrary internal services from the application server, potentially exposing sensitive internal resources and bypassing network segmentation. The inclusion of response data in error messages makes this particularly effective for data exfiltration. Affected versions
0.4.1
0.4.2
0.4.3
0.4.4
0.4.4.post1
0.4.4.post2
0.4.5
0.4.6
0.4.6.post1
0.4.6.post2
0.4.7
0.4.8
+ 76 more Show less
0.5.0
0.5.1
0.6.0
0.6.1
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.4.post0
0.7.4.post1
0.7.5.post1
0.7.5.post2
0.8.0
0.8.0.post0
0.8.1
0.8.1.post0
0.8.2
0.8.2.post0
0.9.0
0.9.0.post2
0.9.0.post3
0.9.0.post4
0.9.0.post5
0.9.1
0.9.1.post0
0.9.1.post1
0.9.1.post2
1.0.0
1.0.0.post0
1.0.0.post1
1.0.0.post2
1.0.0.post3
1.0.1
1.0.2
1.0.2.post0
1.1.0
1.1.0rc0
1.1.1
1.10.0
1.10.0.post0
1.10.1
1.11.0
1.12.0
1.12.0.post0
1.12.1
1.13.0
1.13.1
1.14.0
1.14.0.post0
1.15.0
1.2
1.3
1.3.post0
1.3.post1
1.4
1.4.1
1.4.1.post0
1.4.1.post1
1.5.0
1.5.0.post0
1.6.0
1.7.0
1.7.1
1.7.2
1.7.3
1.8.0
1.8.1
1.8.2
1.8.2.post0
1.8.2.post1
1.9.0
1.9.1
1.9.1.post0
1.9.2
1.9.2.post0
Fixed in
1.16.0
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-25296
PYSEC-2026-1504
GHSA-wpq5-3366-mqw4
Jul 07, 2026
Label Studio allows Cross-Site Scripting (XSS) via GET request to `/projects/upload-example` endpoint
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
DescriptionLabel Studio's The vulnerability exists because the upload-example endpoint renders user-provided HTML content without proper sanitization on a GET request. This allows attackers to inject and execute arbitrary JavaScript in victims' browsers by getting them to visit a maliciously crafted URL. This is considered vulnerable because it enables attackers to execute JavaScript in victims' contexts, potentially allowing theft of sensitive data, session hijacking, or other malicious actions. Steps to reproduce
When executed, the payload causes the application to render an HTML page containing an img tag that fails to load, triggering the onerror event handler which executes base64-decoded JavaScript, demonstrating successful XSS execution in the victim's browser. Mitigations
ImpactThe vulnerability requires no special privileges and can be exploited by getting a victim to visit a crafted URL. The impact is high as it allows arbitrary JavaScript execution in victims' browsers, potentially exposing sensitive data or enabling account takeover through session theft. Affected versions
0.4.1
0.4.2
0.4.3
0.4.4
0.4.4.post1
0.4.4.post2
0.4.5
0.4.6
0.4.6.post1
0.4.6.post2
0.4.7
0.4.8
+ 76 more Show less
0.5.0
0.5.1
0.6.0
0.6.1
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.4.post0
0.7.4.post1
0.7.5.post1
0.7.5.post2
0.8.0
0.8.0.post0
0.8.1
0.8.1.post0
0.8.2
0.8.2.post0
0.9.0
0.9.0.post2
0.9.0.post3
0.9.0.post4
0.9.0.post5
0.9.1
0.9.1.post0
0.9.1.post1
0.9.1.post2
1.0.0
1.0.0.post0
1.0.0.post1
1.0.0.post2
1.0.0.post3
1.0.1
1.0.2
1.0.2.post0
1.1.0
1.1.0rc0
1.1.1
1.10.0
1.10.0.post0
1.10.1
1.11.0
1.12.0
1.12.0.post0
1.12.1
1.13.0
1.13.1
1.14.0
1.14.0.post0
1.15.0
1.2
1.3
1.3.post0
1.3.post1
1.4
1.4.1
1.4.1.post0
1.4.1.post1
1.5.0
1.5.0.post0
1.6.0
1.7.0
1.7.1
1.7.2
1.7.3
1.8.0
1.8.1
1.8.2
1.8.2.post0
1.8.2.post1
1.9.0
1.9.1
1.9.1.post0
1.9.2
1.9.2.post0
Fixed in
1.16.0
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-47783
GHSA-8jhr-wpcm-hh4h
PYSEC-2025-124
May 15, 2025
label-studio vulnerable to Cross-Site Scripting (Reflected) via the label_config parameter.
High
Network
Low
None
SummaryThe vulnerability allows an attacker to inject a malicious script into the context of a web page, which can lead to data theft, unauthorized actions on behalf of the user, and other attacks. DetailsThe vulnerability is reproducible when sending a properly formatted request to the
The vulnerability is specifically located in line 57, where HttpResponse is used.
PoCSend the following request after changing the
Or you can create a vulnerable HTML page by changing
Impact
Affected versions
0.4.1
0.4.2
0.4.3
0.4.4
0.4.4.post1
0.4.4.post2
0.4.5
0.4.6
0.4.6.post1
0.4.6.post2
0.4.7
0.4.8
+ 78 more Show less
0.5.0
0.5.1
0.6.0
0.6.1
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.4.post0
0.7.4.post1
0.7.5.post1
0.7.5.post2
0.8.0
0.8.0.post0
0.8.1
0.8.1.post0
0.8.2
0.8.2.post0
0.9.0
0.9.0.post2
0.9.0.post3
0.9.0.post4
0.9.0.post5
0.9.1
0.9.1.post0
0.9.1.post1
0.9.1.post2
1.0.0
1.0.0.post0
1.0.0.post1
1.0.0.post2
1.0.0.post3
1.0.1
1.0.2
1.0.2.post0
1.1.0
1.1.0rc0
1.1.1
1.10.0
1.10.0.post0
1.10.1
1.11.0
1.12.0
1.12.0.post0
1.12.1
1.13.0
1.13.1
1.14.0
1.14.0.post0
1.15.0
1.16.0
1.17.0
1.2
1.3
1.3.post0
1.3.post1
1.4
1.4.1
1.4.1.post0
1.4.1.post1
1.5.0
1.5.0.post0
1.6.0
1.7.0
1.7.1
1.7.2
1.7.3
1.8.0
1.8.1
1.8.2
1.8.2.post0
1.8.2.post1
1.9.0
1.9.1
1.9.1.post0
1.9.2
1.9.2.post0
Fixed in
1.18.0
References
Updated Jun 06, 2026 · Source: OSV.dev
CVE-2024-26152
PYSEC-2024-249
GHSA-6xv9-957j-qfhg
Feb 22, 2024
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
SummaryOn all Label Studio versions prior to 1.11.0, data imported via file upload feature is not properly sanitized prior to being rendered within a DetailsNeed permission to use the "data import" function. This was reproduced on Label Studio 1.10.1. PoC
The following are the contents of the files used in the PoC
ImpactMalicious scripts can be injected into the code, and when linked with vulnerabilities such as CSRF, it can cause even greater damage. In particular, It can become a source of further attacks, especially when linked to social engineering. Affected versions
0.4.1
0.4.2
0.4.3
0.4.4
0.4.4.post1
0.4.4.post2
0.4.5
0.4.6
0.4.6.post1
0.4.6.post2
0.4.7
0.4.8
+ 113 more Show less
0.5.0
0.5.1
0.6.0
0.6.1
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.4.post0
0.7.4.post1
0.7.5.post1
0.7.5.post2
0.8.0
0.8.0.post0
0.8.1
0.8.1.post0
0.8.2
0.8.2.post0
0.9.0
0.9.0.post2
0.9.0.post3
0.9.0.post4
0.9.0.post5
0.9.1
0.9.1.post0
0.9.1.post1
0.9.1.post2
1.0.0
1.0.0.post0
1.0.0.post1
1.0.0.post2
1.0.0.post3
1.0.1
1.0.2
1.0.2.post0
1.1.0
1.1.0rc0
1.1.1
1.10.0
1.10.0.post0
1.10.1
1.2
1.3
1.3.post0
1.3.post1
1.4
1.4.1
1.4.1.post0
1.4.1.post1
1.5.0
1.5.0.post0
1.6.0
1.7.0
1.7.1
1.7.2
1.7.3
1.8.0
1.8.1
1.8.2
1.8.2.post0
1.8.2.post1
1.9.0
1.9.1
1.9.1.post0
1.9.2
1.9.2.post0
v1.4.1
v1.4.0
v1.3.0
v1.2.0
v1.1.1
v1.1.0
v1.0.2
v1.0.1
v1.0.0
v0.9.1.post1
v0.9.1.post0
v0.9.0.post5
v0.9.0.post4
v0.9.0.post3
v0.9.0
v0.8.2
v0.8.1
v0.8.0
v0.7.5.post0
v0.7.3
v0.7.2
v0.7.1
v0.7.0
v0.6.1
v0.6.0
v0.5.1
v0.4.8
v0.4.7
v0.4.6
v0.4.5
v0.4.4
v0.4.0
v0.3.0
v0.2.2
v.0.2.1-8
v.0.2.1-5
v.0.2.1-4
v.0.2.1-3
v.0.2.1-2
v.0.2.0
v.0.1.6
v.0.1.5
v.0.1.4
v.0.1.2
v.0.1.1
v.0.1.0
Fixed in
1.11.0
References
Updated Jun 10, 2026 · Source: OSV.dev
CVE-2023-47116
GHSA-p59w-9gqw-wj8r
PYSEC-2024-127
Jan 31, 2024
Label Studio SSRF on Import Bypassing `SSRF_PROTECTION_ENABLED` Protections
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
IntroductionThis write-up describes a vulnerability found in Label Studio, a popular open source data labeling tool. The vulnerability affects all versions of Label Studio prior to OverviewLabel Studio's SSRF protections that can be enabled by setting the DescriptionThe following
The
The issue here is the SSRF validation is only performed before the request is sent, and does not validate the destination IP address. Therefore, an attacker can either redirect the request or perform a DNS rebinding attack to bypass this protection. Proof of ConceptBoth the HTTP redirection and DNS rebinding methods for bypassing Label Studio's SSRF protections are explained below. HTTP RedirectionThe python
DNS Rebinding AttackDNS rebinding can bypass SSRF protections by resolving to an external IP address for the first resolution, but when the request is sent resolves to an internal IP address that is blocked. For an example, the domain ImpactSSRF vulnerabilities pose a significant risk on cloud environments, since instance credentials are managed by internal web APIs. An attacker can bypass Label Studio's SSRF protections to access internal web servers and partially compromise the confidentiality of those internal servers. Remediation Advice
Discovered
Affected versions
0.4.1
0.4.2
0.4.3
0.4.4
0.4.4.post1
0.4.4.post2
0.4.5
0.4.6
0.4.6.post1
0.4.6.post2
0.4.7
0.4.8
+ 67 more Show less
0.5.0
0.5.1
0.6.0
0.6.1
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.4.post0
0.7.4.post1
0.7.5.post1
0.7.5.post2
0.8.0
0.8.0.post0
0.8.1
0.8.1.post0
0.8.2
0.8.2.post0
0.9.0
0.9.0.post2
0.9.0.post3
0.9.0.post4
0.9.0.post5
0.9.1
0.9.1.post0
0.9.1.post1
0.9.1.post2
1.0.0
1.0.0.post0
1.0.0.post1
1.0.0.post2
1.0.0.post3
1.0.1
1.0.2
1.0.2.post0
1.1.0
1.1.0rc0
1.1.1
1.10.0
1.10.0.post0
1.10.1
1.2
1.3
1.3.post0
1.3.post1
1.4
1.4.1
1.4.1.post0
1.4.1.post1
1.5.0
1.5.0.post0
1.6.0
1.7.0
1.7.1
1.7.2
1.7.3
1.8.0
1.8.1
1.8.2
1.8.2.post0
1.8.2.post1
1.9.0
1.9.1
1.9.1.post0
1.9.2
1.9.2.post0
Fixed in
1.11.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-23633
GHSA-fq23-g58m-799r
PYSEC-2024-128
Jan 24, 2024
Cross-site Scripting Vulnerability on Data Import
4.7
/ 10
Medium
Network
Low
None
Required
Changed
Low
None
None
IntroductionThis write-up describes a vulnerability found in Label Studio, a popular open source data labeling tool. The vulnerability affects all versions of Label Studio prior to OverviewLabel Studio had a remote import feature allowed users to import data from a remote web source, that was downloaded and could be viewed on the website. This feature could had been abused to download a HTML file that executed malicious JavaScript code in the context of the Label Studio website. DescriptionThe following code snippet in Label Studio showed that is a URL passed the SSRF verification checks, the contents of the file would be downloaded using the filename in the URL.
The downloaded file path could then be retrieved by sending a request to
Since the Proof of ConceptBelow were the steps to recreate this issue:
ImpactExecuting arbitrary JavaScript could result in an attacker performing malicious actions on Label Studio users if they visit the crafted avatar image. For an example, an attacker can craft a JavaScript payload that adds a new Django Super Administrator user if a Django administrator visits the image. Remediation Advice
Discovered
Affected versions
0.4.1
0.4.2
0.4.3
0.4.4
0.4.4.post1
0.4.4.post2
0.4.5
0.4.6
0.4.6.post1
0.4.6.post2
0.4.7
0.4.8
+ 66 more Show less
0.5.0
0.5.1
0.6.0
0.6.1
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.4.post0
0.7.4.post1
0.7.5.post1
0.7.5.post2
0.8.0
0.8.0.post0
0.8.1
0.8.1.post0
0.8.2
0.8.2.post0
0.9.0
0.9.0.post2
0.9.0.post3
0.9.0.post4
0.9.0.post5
0.9.1
0.9.1.post0
0.9.1.post1
0.9.1.post2
1.0.0
1.0.0.post0
1.0.0.post1
1.0.0.post2
1.0.0.post3
1.0.1
1.0.2
1.0.2.post0
1.1.0
1.1.0rc0
1.1.1
1.10.0
1.10.0.post0
1.2
1.3
1.3.post0
1.3.post1
1.4
1.4.1
1.4.1.post0
1.4.1.post1
1.5.0
1.5.0.post0
1.6.0
1.7.0
1.7.1
1.7.2
1.7.3
1.8.0
1.8.1
1.8.2
1.8.2.post0
1.8.2.post1
1.9.0
1.9.1
1.9.1.post0
1.9.2
1.9.2.post0
Fixed in
1.10.1
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
1.9.2.post0
pre
8 CVEs
CVE-2026-22033
PYSEC-2026-1502
GHSA-2mq9-hm29-8qch
Jul 07, 2026
Label Studio is vulnerable to full account takeover by chaining Stored XSS + IDOR in User Profile via custom_hotkeys field
Critical
Network
Low
Low
None
PrologueThese vulnerabilities have been found and chained by DCODX-AI. Validation of the exploit chain has been confirmed manually. SummaryA persistent stored cross-site scripting (XSS) vulnerability exists in the custom_hotkeys functionality of the application. An authenticated attacker (or one who can trick a user/administrator into updating their custom_hotkeys) can inject JavaScript code that executes in other users’ browsers when those users load any page using the DetailsWithin
Here, user.custom_hotkeys is run through json_dumps_ensure_ascii (in In
The serializer allows
When another user loads a page using templates/base.html (for example PoC
Example request
Example response
ImpactExploitation impact:
Who is impacted:
Affected versions
0.4.1
0.4.2
0.4.3
0.4.4
0.4.4.post1
0.4.4.post2
0.4.5
0.4.6
0.4.6.post1
0.4.6.post2
0.4.7
0.4.8
+ 83 more Show less
0.5.0
0.5.1
0.6.0
0.6.1
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.4.post0
0.7.4.post1
0.7.5.post1
0.7.5.post2
0.8.0
0.8.0.post0
0.8.1
0.8.1.post0
0.8.2
0.8.2.post0
0.9.0
0.9.0.post2
0.9.0.post3
0.9.0.post4
0.9.0.post5
0.9.1
0.9.1.post0
0.9.1.post1
0.9.1.post2
1.0.0
1.0.0.post0
1.0.0.post1
1.0.0.post2
1.0.0.post3
1.0.1
1.0.2
1.0.2.post0
1.1.0
1.1.0rc0
1.1.1
1.10.0
1.10.0.post0
1.10.1
1.11.0
1.12.0
1.12.0.post0
1.12.1
1.13.0
1.13.1
1.14.0
1.14.0.post0
1.15.0
1.16.0
1.17.0
1.18.0
1.19.0
1.2
1.20.0
1.21.0
1.22.0
1.3
1.3.post0
1.3.post1
1.4
1.4.1
1.4.1.post0
1.4.1.post1
1.5.0
1.5.0.post0
1.6.0
1.7.0
1.7.1
1.7.2
1.7.3
1.8.0
1.8.1
1.8.2
1.8.2.post0
1.8.2.post1
1.9.0
1.9.1
1.9.1.post0
1.9.2
1.9.2.post0
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-25297
PYSEC-2026-1503
GHSA-m238-fmcw-wh58
Jul 07, 2026
Label Studio allows Server-Side Request Forgery in the S3 Storage Endpoint
8.6
/ 10
High
Network
Low
None
None
Changed
High
None
None
DescriptionLabel Studio's S3 storage integration feature contains a Server-Side Request Forgery (SSRF) vulnerability in its endpoint configuration. When creating an S3 storage connection, the application allows users to specify a custom S3 endpoint URL via the s3_endpoint parameter. This endpoint URL is passed directly to the boto3 AWS SDK without proper validation or restrictions on the protocol or destination. The vulnerability allows an attacker to make the application send HTTP requests to arbitrary internal services by specifying them as the S3 endpoint. When the storage sync operation is triggered, the application attempts to make S3 API calls to the specified endpoint, effectively making HTTP requests to the target service and returning the response in error messages. This SSRF vulnerability enables attackers to bypass network segmentation and access internal services that should not be accessible from the external network. The vulnerability is particularly severe because error messages from failed requests contain the full response body, allowing data exfiltration from internal services. Steps to reproduce
The application will attempt to connect to the specified endpoint URL as if it were an S3 service. When the request fails due to invalid S3 API responses, the error message will contain the raw response from the internal service, allowing access to internal resources. Mitigations
ImpactThis vulnerability has high severity as it allows authenticated users to make requests to arbitrary internal services from the application server, potentially exposing sensitive internal resources and bypassing network segmentation. The inclusion of response data in error messages makes this particularly effective for data exfiltration. Affected versions
0.4.1
0.4.2
0.4.3
0.4.4
0.4.4.post1
0.4.4.post2
0.4.5
0.4.6
0.4.6.post1
0.4.6.post2
0.4.7
0.4.8
+ 76 more Show less
0.5.0
0.5.1
0.6.0
0.6.1
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.4.post0
0.7.4.post1
0.7.5.post1
0.7.5.post2
0.8.0
0.8.0.post0
0.8.1
0.8.1.post0
0.8.2
0.8.2.post0
0.9.0
0.9.0.post2
0.9.0.post3
0.9.0.post4
0.9.0.post5
0.9.1
0.9.1.post0
0.9.1.post1
0.9.1.post2
1.0.0
1.0.0.post0
1.0.0.post1
1.0.0.post2
1.0.0.post3
1.0.1
1.0.2
1.0.2.post0
1.1.0
1.1.0rc0
1.1.1
1.10.0
1.10.0.post0
1.10.1
1.11.0
1.12.0
1.12.0.post0
1.12.1
1.13.0
1.13.1
1.14.0
1.14.0.post0
1.15.0
1.2
1.3
1.3.post0
1.3.post1
1.4
1.4.1
1.4.1.post0
1.4.1.post1
1.5.0
1.5.0.post0
1.6.0
1.7.0
1.7.1
1.7.2
1.7.3
1.8.0
1.8.1
1.8.2
1.8.2.post0
1.8.2.post1
1.9.0
1.9.1
1.9.1.post0
1.9.2
1.9.2.post0
Fixed in
1.16.0
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-25296
PYSEC-2026-1504
GHSA-wpq5-3366-mqw4
Jul 07, 2026
Label Studio allows Cross-Site Scripting (XSS) via GET request to `/projects/upload-example` endpoint
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
DescriptionLabel Studio's The vulnerability exists because the upload-example endpoint renders user-provided HTML content without proper sanitization on a GET request. This allows attackers to inject and execute arbitrary JavaScript in victims' browsers by getting them to visit a maliciously crafted URL. This is considered vulnerable because it enables attackers to execute JavaScript in victims' contexts, potentially allowing theft of sensitive data, session hijacking, or other malicious actions. Steps to reproduce
When executed, the payload causes the application to render an HTML page containing an img tag that fails to load, triggering the onerror event handler which executes base64-decoded JavaScript, demonstrating successful XSS execution in the victim's browser. Mitigations
ImpactThe vulnerability requires no special privileges and can be exploited by getting a victim to visit a crafted URL. The impact is high as it allows arbitrary JavaScript execution in victims' browsers, potentially exposing sensitive data or enabling account takeover through session theft. Affected versions
0.4.1
0.4.2
0.4.3
0.4.4
0.4.4.post1
0.4.4.post2
0.4.5
0.4.6
0.4.6.post1
0.4.6.post2
0.4.7
0.4.8
+ 76 more Show less
0.5.0
0.5.1
0.6.0
0.6.1
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.4.post0
0.7.4.post1
0.7.5.post1
0.7.5.post2
0.8.0
0.8.0.post0
0.8.1
0.8.1.post0
0.8.2
0.8.2.post0
0.9.0
0.9.0.post2
0.9.0.post3
0.9.0.post4
0.9.0.post5
0.9.1
0.9.1.post0
0.9.1.post1
0.9.1.post2
1.0.0
1.0.0.post0
1.0.0.post1
1.0.0.post2
1.0.0.post3
1.0.1
1.0.2
1.0.2.post0
1.1.0
1.1.0rc0
1.1.1
1.10.0
1.10.0.post0
1.10.1
1.11.0
1.12.0
1.12.0.post0
1.12.1
1.13.0
1.13.1
1.14.0
1.14.0.post0
1.15.0
1.2
1.3
1.3.post0
1.3.post1
1.4
1.4.1
1.4.1.post0
1.4.1.post1
1.5.0
1.5.0.post0
1.6.0
1.7.0
1.7.1
1.7.2
1.7.3
1.8.0
1.8.1
1.8.2
1.8.2.post0
1.8.2.post1
1.9.0
1.9.1
1.9.1.post0
1.9.2
1.9.2.post0
Fixed in
1.16.0
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-47783
GHSA-8jhr-wpcm-hh4h
PYSEC-2025-124
May 15, 2025
label-studio vulnerable to Cross-Site Scripting (Reflected) via the label_config parameter.
High
Network
Low
None
SummaryThe vulnerability allows an attacker to inject a malicious script into the context of a web page, which can lead to data theft, unauthorized actions on behalf of the user, and other attacks. DetailsThe vulnerability is reproducible when sending a properly formatted request to the
The vulnerability is specifically located in line 57, where HttpResponse is used.
PoCSend the following request after changing the
Or you can create a vulnerable HTML page by changing
Impact
Affected versions
0.4.1
0.4.2
0.4.3
0.4.4
0.4.4.post1
0.4.4.post2
0.4.5
0.4.6
0.4.6.post1
0.4.6.post2
0.4.7
0.4.8
+ 78 more Show less
0.5.0
0.5.1
0.6.0
0.6.1
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.4.post0
0.7.4.post1
0.7.5.post1
0.7.5.post2
0.8.0
0.8.0.post0
0.8.1
0.8.1.post0
0.8.2
0.8.2.post0
0.9.0
0.9.0.post2
0.9.0.post3
0.9.0.post4
0.9.0.post5
0.9.1
0.9.1.post0
0.9.1.post1
0.9.1.post2
1.0.0
1.0.0.post0
1.0.0.post1
1.0.0.post2
1.0.0.post3
1.0.1
1.0.2
1.0.2.post0
1.1.0
1.1.0rc0
1.1.1
1.10.0
1.10.0.post0
1.10.1
1.11.0
1.12.0
1.12.0.post0
1.12.1
1.13.0
1.13.1
1.14.0
1.14.0.post0
1.15.0
1.16.0
1.17.0
1.2
1.3
1.3.post0
1.3.post1
1.4
1.4.1
1.4.1.post0
1.4.1.post1
1.5.0
1.5.0.post0
1.6.0
1.7.0
1.7.1
1.7.2
1.7.3
1.8.0
1.8.1
1.8.2
1.8.2.post0
1.8.2.post1
1.9.0
1.9.1
1.9.1.post0
1.9.2
1.9.2.post0
Fixed in
1.18.0
References
Updated Jun 06, 2026 · Source: OSV.dev
CVE-2024-26152
PYSEC-2024-249
GHSA-6xv9-957j-qfhg
Feb 22, 2024
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
SummaryOn all Label Studio versions prior to 1.11.0, data imported via file upload feature is not properly sanitized prior to being rendered within a DetailsNeed permission to use the "data import" function. This was reproduced on Label Studio 1.10.1. PoC
The following are the contents of the files used in the PoC
ImpactMalicious scripts can be injected into the code, and when linked with vulnerabilities such as CSRF, it can cause even greater damage. In particular, It can become a source of further attacks, especially when linked to social engineering. Affected versions
0.4.1
0.4.2
0.4.3
0.4.4
0.4.4.post1
0.4.4.post2
0.4.5
0.4.6
0.4.6.post1
0.4.6.post2
0.4.7
0.4.8
+ 113 more Show less
0.5.0
0.5.1
0.6.0
0.6.1
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.4.post0
0.7.4.post1
0.7.5.post1
0.7.5.post2
0.8.0
0.8.0.post0
0.8.1
0.8.1.post0
0.8.2
0.8.2.post0
0.9.0
0.9.0.post2
0.9.0.post3
0.9.0.post4
0.9.0.post5
0.9.1
0.9.1.post0
0.9.1.post1
0.9.1.post2
1.0.0
1.0.0.post0
1.0.0.post1
1.0.0.post2
1.0.0.post3
1.0.1
1.0.2
1.0.2.post0
1.1.0
1.1.0rc0
1.1.1
1.10.0
1.10.0.post0
1.10.1
1.2
1.3
1.3.post0
1.3.post1
1.4
1.4.1
1.4.1.post0
1.4.1.post1
1.5.0
1.5.0.post0
1.6.0
1.7.0
1.7.1
1.7.2
1.7.3
1.8.0
1.8.1
1.8.2
1.8.2.post0
1.8.2.post1
1.9.0
1.9.1
1.9.1.post0
1.9.2
1.9.2.post0
v1.4.1
v1.4.0
v1.3.0
v1.2.0
v1.1.1
v1.1.0
v1.0.2
v1.0.1
v1.0.0
v0.9.1.post1
v0.9.1.post0
v0.9.0.post5
v0.9.0.post4
v0.9.0.post3
v0.9.0
v0.8.2
v0.8.1
v0.8.0
v0.7.5.post0
v0.7.3
v0.7.2
v0.7.1
v0.7.0
v0.6.1
v0.6.0
v0.5.1
v0.4.8
v0.4.7
v0.4.6
v0.4.5
v0.4.4
v0.4.0
v0.3.0
v0.2.2
v.0.2.1-8
v.0.2.1-5
v.0.2.1-4
v.0.2.1-3
v.0.2.1-2
v.0.2.0
v.0.1.6
v.0.1.5
v.0.1.4
v.0.1.2
v.0.1.1
v.0.1.0
Fixed in
1.11.0
References
Updated Jun 10, 2026 · Source: OSV.dev
CVE-2023-47116
GHSA-p59w-9gqw-wj8r
PYSEC-2024-127
Jan 31, 2024
Label Studio SSRF on Import Bypassing `SSRF_PROTECTION_ENABLED` Protections
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
IntroductionThis write-up describes a vulnerability found in Label Studio, a popular open source data labeling tool. The vulnerability affects all versions of Label Studio prior to OverviewLabel Studio's SSRF protections that can be enabled by setting the DescriptionThe following
The
The issue here is the SSRF validation is only performed before the request is sent, and does not validate the destination IP address. Therefore, an attacker can either redirect the request or perform a DNS rebinding attack to bypass this protection. Proof of ConceptBoth the HTTP redirection and DNS rebinding methods for bypassing Label Studio's SSRF protections are explained below. HTTP RedirectionThe python
DNS Rebinding AttackDNS rebinding can bypass SSRF protections by resolving to an external IP address for the first resolution, but when the request is sent resolves to an internal IP address that is blocked. For an example, the domain ImpactSSRF vulnerabilities pose a significant risk on cloud environments, since instance credentials are managed by internal web APIs. An attacker can bypass Label Studio's SSRF protections to access internal web servers and partially compromise the confidentiality of those internal servers. Remediation Advice
Discovered
Affected versions
0.4.1
0.4.2
0.4.3
0.4.4
0.4.4.post1
0.4.4.post2
0.4.5
0.4.6
0.4.6.post1
0.4.6.post2
0.4.7
0.4.8
+ 67 more Show less
0.5.0
0.5.1
0.6.0
0.6.1
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.4.post0
0.7.4.post1
0.7.5.post1
0.7.5.post2
0.8.0
0.8.0.post0
0.8.1
0.8.1.post0
0.8.2
0.8.2.post0
0.9.0
0.9.0.post2
0.9.0.post3
0.9.0.post4
0.9.0.post5
0.9.1
0.9.1.post0
0.9.1.post1
0.9.1.post2
1.0.0
1.0.0.post0
1.0.0.post1
1.0.0.post2
1.0.0.post3
1.0.1
1.0.2
1.0.2.post0
1.1.0
1.1.0rc0
1.1.1
1.10.0
1.10.0.post0
1.10.1
1.2
1.3
1.3.post0
1.3.post1
1.4
1.4.1
1.4.1.post0
1.4.1.post1
1.5.0
1.5.0.post0
1.6.0
1.7.0
1.7.1
1.7.2
1.7.3
1.8.0
1.8.1
1.8.2
1.8.2.post0
1.8.2.post1
1.9.0
1.9.1
1.9.1.post0
1.9.2
1.9.2.post0
Fixed in
1.11.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-23633
GHSA-fq23-g58m-799r
PYSEC-2024-128
Jan 24, 2024
Cross-site Scripting Vulnerability on Data Import
4.7
/ 10
Medium
Network
Low
None
Required
Changed
Low
None
None
IntroductionThis write-up describes a vulnerability found in Label Studio, a popular open source data labeling tool. The vulnerability affects all versions of Label Studio prior to OverviewLabel Studio had a remote import feature allowed users to import data from a remote web source, that was downloaded and could be viewed on the website. This feature could had been abused to download a HTML file that executed malicious JavaScript code in the context of the Label Studio website. DescriptionThe following code snippet in Label Studio showed that is a URL passed the SSRF verification checks, the contents of the file would be downloaded using the filename in the URL.
The downloaded file path could then be retrieved by sending a request to
Since the Proof of ConceptBelow were the steps to recreate this issue:
ImpactExecuting arbitrary JavaScript could result in an attacker performing malicious actions on Label Studio users if they visit the crafted avatar image. For an example, an attacker can craft a JavaScript payload that adds a new Django Super Administrator user if a Django administrator visits the image. Remediation Advice
Discovered
Affected versions
0.4.1
0.4.2
0.4.3
0.4.4
0.4.4.post1
0.4.4.post2
0.4.5
0.4.6
0.4.6.post1
0.4.6.post2
0.4.7
0.4.8
+ 66 more Show less
0.5.0
0.5.1
0.6.0
0.6.1
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.4.post0
0.7.4.post1
0.7.5.post1
0.7.5.post2
0.8.0
0.8.0.post0
0.8.1
0.8.1.post0
0.8.2
0.8.2.post0
0.9.0
0.9.0.post2
0.9.0.post3
0.9.0.post4
0.9.0.post5
0.9.1
0.9.1.post0
0.9.1.post1
0.9.1.post2
1.0.0
1.0.0.post0
1.0.0.post1
1.0.0.post2
1.0.0.post3
1.0.1
1.0.2
1.0.2.post0
1.1.0
1.1.0rc0
1.1.1
1.10.0
1.10.0.post0
1.2
1.3
1.3.post0
1.3.post1
1.4
1.4.1
1.4.1.post0
1.4.1.post1
1.5.0
1.5.0.post0
1.6.0
1.7.0
1.7.1
1.7.2
1.7.3
1.8.0
1.8.1
1.8.2
1.8.2.post0
1.8.2.post1
1.9.0
1.9.1
1.9.1.post0
1.9.2
1.9.2.post0
Fixed in
1.10.1
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2023-47115
GHSA-q68h-xwq5-mm7x
PYSEC-2024-126
Jan 24, 2024
Cross-site Scripting Vulnerability on Avatar Upload
7.1
/ 10
High
Network
Low
None
Required
Changed
Low
Low
Low
IntroductionThis write-up describes a vulnerability found in Label Studio, a popular open source data labeling tool. The vulnerability affects all versions of Label Studio prior to OverviewLabel Studio has a cross-site scripting (XSS) vulnerability that could be exploited when an authenticated user uploads a crafted image file for their avatar that gets rendered as a HTML file on the website. DescriptionThe following code snippet in Label Studio shows that the only verification check is that the file is an image by extracting the dimensions from the file.
Label Studio serves avatar images using Django's built-in
The issue with the Django Proof of ConceptBelow are the steps to reproduce this issue and execute JavaScript code in the context of the Label Studio website.
ImpactExecuting arbitrary JavaScript could result in an attacker performing malicious actions on Label Studio users if they visit the crafted avatar image. For an example, an attacker can craft a JavaScript payload that adds a new Django Super Administrator user if a Django administrator visits the image. Remediation Advice
Discovered
Affected versions
0.4.1
0.4.2
0.4.3
0.4.4
0.4.4.post1
0.4.4.post2
0.4.5
0.4.6
0.4.6.post1
0.4.6.post2
0.4.7
0.4.8
+ 62 more Show less
0.5.0
0.5.1
0.6.0
0.6.1
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.4.post0
0.7.4.post1
0.7.5.post1
0.7.5.post2
0.8.0
0.8.0.post0
0.8.1
0.8.1.post0
0.8.2
0.8.2.post0
0.9.0
0.9.0.post2
0.9.0.post3
0.9.0.post4
0.9.0.post5
0.9.1
0.9.1.post0
0.9.1.post1
0.9.1.post2
1.0.0
1.0.0.post0
1.0.0.post1
1.0.0.post2
1.0.0.post3
1.0.1
1.0.2
1.0.2.post0
1.1.0
1.1.0rc0
1.1.1
1.2
1.3
1.3.post0
1.3.post1
1.4
1.4.1
1.4.1.post0
1.4.1.post1
1.5.0
1.5.0.post0
1.6.0
1.7.0
1.7.1
1.7.2
1.7.3
1.8.0
1.8.1
1.8.2
1.8.2.post0
1.8.2.post1
1.9.0
1.9.1
1.9.1.post0
Fixed in
1.9.2
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
1.9.2
patch
8 CVEs
CVE-2026-22033
PYSEC-2026-1502
GHSA-2mq9-hm29-8qch
Jul 07, 2026
Label Studio is vulnerable to full account takeover by chaining Stored XSS + IDOR in User Profile via custom_hotkeys field
Critical
Network
Low
Low
None
PrologueThese vulnerabilities have been found and chained by DCODX-AI. Validation of the exploit chain has been confirmed manually. SummaryA persistent stored cross-site scripting (XSS) vulnerability exists in the custom_hotkeys functionality of the application. An authenticated attacker (or one who can trick a user/administrator into updating their custom_hotkeys) can inject JavaScript code that executes in other users’ browsers when those users load any page using the DetailsWithin
Here, user.custom_hotkeys is run through json_dumps_ensure_ascii (in In
The serializer allows
When another user loads a page using templates/base.html (for example PoC
Example request
Example response
ImpactExploitation impact:
Who is impacted:
Affected versions
0.4.1
0.4.2
0.4.3
0.4.4
0.4.4.post1
0.4.4.post2
0.4.5
0.4.6
0.4.6.post1
0.4.6.post2
0.4.7
0.4.8
+ 83 more Show less
0.5.0
0.5.1
0.6.0
0.6.1
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.4.post0
0.7.4.post1
0.7.5.post1
0.7.5.post2
0.8.0
0.8.0.post0
0.8.1
0.8.1.post0
0.8.2
0.8.2.post0
0.9.0
0.9.0.post2
0.9.0.post3
0.9.0.post4
0.9.0.post5
0.9.1
0.9.1.post0
0.9.1.post1
0.9.1.post2
1.0.0
1.0.0.post0
1.0.0.post1
1.0.0.post2
1.0.0.post3
1.0.1
1.0.2
1.0.2.post0
1.1.0
1.1.0rc0
1.1.1
1.10.0
1.10.0.post0
1.10.1
1.11.0
1.12.0
1.12.0.post0
1.12.1
1.13.0
1.13.1
1.14.0
1.14.0.post0
1.15.0
1.16.0
1.17.0
1.18.0
1.19.0
1.2
1.20.0
1.21.0
1.22.0
1.3
1.3.post0
1.3.post1
1.4
1.4.1
1.4.1.post0
1.4.1.post1
1.5.0
1.5.0.post0
1.6.0
1.7.0
1.7.1
1.7.2
1.7.3
1.8.0
1.8.1
1.8.2
1.8.2.post0
1.8.2.post1
1.9.0
1.9.1
1.9.1.post0
1.9.2
1.9.2.post0
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-25297
PYSEC-2026-1503
GHSA-m238-fmcw-wh58
Jul 07, 2026
Label Studio allows Server-Side Request Forgery in the S3 Storage Endpoint
8.6
/ 10
High
Network
Low
None
None
Changed
High
None
None
DescriptionLabel Studio's S3 storage integration feature contains a Server-Side Request Forgery (SSRF) vulnerability in its endpoint configuration. When creating an S3 storage connection, the application allows users to specify a custom S3 endpoint URL via the s3_endpoint parameter. This endpoint URL is passed directly to the boto3 AWS SDK without proper validation or restrictions on the protocol or destination. The vulnerability allows an attacker to make the application send HTTP requests to arbitrary internal services by specifying them as the S3 endpoint. When the storage sync operation is triggered, the application attempts to make S3 API calls to the specified endpoint, effectively making HTTP requests to the target service and returning the response in error messages. This SSRF vulnerability enables attackers to bypass network segmentation and access internal services that should not be accessible from the external network. The vulnerability is particularly severe because error messages from failed requests contain the full response body, allowing data exfiltration from internal services. Steps to reproduce
The application will attempt to connect to the specified endpoint URL as if it were an S3 service. When the request fails due to invalid S3 API responses, the error message will contain the raw response from the internal service, allowing access to internal resources. Mitigations
ImpactThis vulnerability has high severity as it allows authenticated users to make requests to arbitrary internal services from the application server, potentially exposing sensitive internal resources and bypassing network segmentation. The inclusion of response data in error messages makes this particularly effective for data exfiltration. Affected versions
0.4.1
0.4.2
0.4.3
0.4.4
0.4.4.post1
0.4.4.post2
0.4.5
0.4.6
0.4.6.post1
0.4.6.post2
0.4.7
0.4.8
+ 76 more Show less
0.5.0
0.5.1
0.6.0
0.6.1
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.4.post0
0.7.4.post1
0.7.5.post1
0.7.5.post2
0.8.0
0.8.0.post0
0.8.1
0.8.1.post0
0.8.2
0.8.2.post0
0.9.0
0.9.0.post2
0.9.0.post3
0.9.0.post4
0.9.0.post5
0.9.1
0.9.1.post0
0.9.1.post1
0.9.1.post2
1.0.0
1.0.0.post0
1.0.0.post1
1.0.0.post2
1.0.0.post3
1.0.1
1.0.2
1.0.2.post0
1.1.0
1.1.0rc0
1.1.1
1.10.0
1.10.0.post0
1.10.1
1.11.0
1.12.0
1.12.0.post0
1.12.1
1.13.0
1.13.1
1.14.0
1.14.0.post0
1.15.0
1.2
1.3
1.3.post0
1.3.post1
1.4
1.4.1
1.4.1.post0
1.4.1.post1
1.5.0
1.5.0.post0
1.6.0
1.7.0
1.7.1
1.7.2
1.7.3
1.8.0
1.8.1
1.8.2
1.8.2.post0
1.8.2.post1
1.9.0
1.9.1
1.9.1.post0
1.9.2
1.9.2.post0
Fixed in
1.16.0
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-25296
PYSEC-2026-1504
GHSA-wpq5-3366-mqw4
Jul 07, 2026
Label Studio allows Cross-Site Scripting (XSS) via GET request to `/projects/upload-example` endpoint
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
DescriptionLabel Studio's The vulnerability exists because the upload-example endpoint renders user-provided HTML content without proper sanitization on a GET request. This allows attackers to inject and execute arbitrary JavaScript in victims' browsers by getting them to visit a maliciously crafted URL. This is considered vulnerable because it enables attackers to execute JavaScript in victims' contexts, potentially allowing theft of sensitive data, session hijacking, or other malicious actions. Steps to reproduce
When executed, the payload causes the application to render an HTML page containing an img tag that fails to load, triggering the onerror event handler which executes base64-decoded JavaScript, demonstrating successful XSS execution in the victim's browser. Mitigations
ImpactThe vulnerability requires no special privileges and can be exploited by getting a victim to visit a crafted URL. The impact is high as it allows arbitrary JavaScript execution in victims' browsers, potentially exposing sensitive data or enabling account takeover through session theft. Affected versions
0.4.1
0.4.2
0.4.3
0.4.4
0.4.4.post1
0.4.4.post2
0.4.5
0.4.6
0.4.6.post1
0.4.6.post2
0.4.7
0.4.8
+ 76 more Show less
0.5.0
0.5.1
0.6.0
0.6.1
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.4.post0
0.7.4.post1
0.7.5.post1
0.7.5.post2
0.8.0
0.8.0.post0
0.8.1
0.8.1.post0
0.8.2
0.8.2.post0
0.9.0
0.9.0.post2
0.9.0.post3
0.9.0.post4
0.9.0.post5
0.9.1
0.9.1.post0
0.9.1.post1
0.9.1.post2
1.0.0
1.0.0.post0
1.0.0.post1
1.0.0.post2
1.0.0.post3
1.0.1
1.0.2
1.0.2.post0
1.1.0
1.1.0rc0
1.1.1
1.10.0
1.10.0.post0
1.10.1
1.11.0
1.12.0
1.12.0.post0
1.12.1
1.13.0
1.13.1
1.14.0
1.14.0.post0
1.15.0
1.2
1.3
1.3.post0
1.3.post1
1.4
1.4.1
1.4.1.post0
1.4.1.post1
1.5.0
1.5.0.post0
1.6.0
1.7.0
1.7.1
1.7.2
1.7.3
1.8.0
1.8.1
1.8.2
1.8.2.post0
1.8.2.post1
1.9.0
1.9.1
1.9.1.post0
1.9.2
1.9.2.post0
Fixed in
1.16.0
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-47783
GHSA-8jhr-wpcm-hh4h
PYSEC-2025-124
May 15, 2025
label-studio vulnerable to Cross-Site Scripting (Reflected) via the label_config parameter.
High
Network
Low
None
SummaryThe vulnerability allows an attacker to inject a malicious script into the context of a web page, which can lead to data theft, unauthorized actions on behalf of the user, and other attacks. DetailsThe vulnerability is reproducible when sending a properly formatted request to the
The vulnerability is specifically located in line 57, where HttpResponse is used.
PoCSend the following request after changing the
Or you can create a vulnerable HTML page by changing
Impact
Affected versions
0.4.1
0.4.2
0.4.3
0.4.4
0.4.4.post1
0.4.4.post2
0.4.5
0.4.6
0.4.6.post1
0.4.6.post2
0.4.7
0.4.8
+ 78 more Show less
0.5.0
0.5.1
0.6.0
0.6.1
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.4.post0
0.7.4.post1
0.7.5.post1
0.7.5.post2
0.8.0
0.8.0.post0
0.8.1
0.8.1.post0
0.8.2
0.8.2.post0
0.9.0
0.9.0.post2
0.9.0.post3
0.9.0.post4
0.9.0.post5
0.9.1
0.9.1.post0
0.9.1.post1
0.9.1.post2
1.0.0
1.0.0.post0
1.0.0.post1
1.0.0.post2
1.0.0.post3
1.0.1
1.0.2
1.0.2.post0
1.1.0
1.1.0rc0
1.1.1
1.10.0
1.10.0.post0
1.10.1
1.11.0
1.12.0
1.12.0.post0
1.12.1
1.13.0
1.13.1
1.14.0
1.14.0.post0
1.15.0
1.16.0
1.17.0
1.2
1.3
1.3.post0
1.3.post1
1.4
1.4.1
1.4.1.post0
1.4.1.post1
1.5.0
1.5.0.post0
1.6.0
1.7.0
1.7.1
1.7.2
1.7.3
1.8.0
1.8.1
1.8.2
1.8.2.post0
1.8.2.post1
1.9.0
1.9.1
1.9.1.post0
1.9.2
1.9.2.post0
Fixed in
1.18.0
References
Updated Jun 06, 2026 · Source: OSV.dev
CVE-2024-26152
PYSEC-2024-249
GHSA-6xv9-957j-qfhg
Feb 22, 2024
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
SummaryOn all Label Studio versions prior to 1.11.0, data imported via file upload feature is not properly sanitized prior to being rendered within a DetailsNeed permission to use the "data import" function. This was reproduced on Label Studio 1.10.1. PoC
The following are the contents of the files used in the PoC
ImpactMalicious scripts can be injected into the code, and when linked with vulnerabilities such as CSRF, it can cause even greater damage. In particular, It can become a source of further attacks, especially when linked to social engineering. Affected versions
0.4.1
0.4.2
0.4.3
0.4.4
0.4.4.post1
0.4.4.post2
0.4.5
0.4.6
0.4.6.post1
0.4.6.post2
0.4.7
0.4.8
+ 113 more Show less
0.5.0
0.5.1
0.6.0
0.6.1
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.4.post0
0.7.4.post1
0.7.5.post1
0.7.5.post2
0.8.0
0.8.0.post0
0.8.1
0.8.1.post0
0.8.2
0.8.2.post0
0.9.0
0.9.0.post2
0.9.0.post3
0.9.0.post4
0.9.0.post5
0.9.1
0.9.1.post0
0.9.1.post1
0.9.1.post2
1.0.0
1.0.0.post0
1.0.0.post1
1.0.0.post2
1.0.0.post3
1.0.1
1.0.2
1.0.2.post0
1.1.0
1.1.0rc0
1.1.1
1.10.0
1.10.0.post0
1.10.1
1.2
1.3
1.3.post0
1.3.post1
1.4
1.4.1
1.4.1.post0
1.4.1.post1
1.5.0
1.5.0.post0
1.6.0
1.7.0
1.7.1
1.7.2
1.7.3
1.8.0
1.8.1
1.8.2
1.8.2.post0
1.8.2.post1
1.9.0
1.9.1
1.9.1.post0
1.9.2
1.9.2.post0
v1.4.1
v1.4.0
v1.3.0
v1.2.0
v1.1.1
v1.1.0
v1.0.2
v1.0.1
v1.0.0
v0.9.1.post1
v0.9.1.post0
v0.9.0.post5
v0.9.0.post4
v0.9.0.post3
v0.9.0
v0.8.2
v0.8.1
v0.8.0
v0.7.5.post0
v0.7.3
v0.7.2
v0.7.1
v0.7.0
v0.6.1
v0.6.0
v0.5.1
v0.4.8
v0.4.7
v0.4.6
v0.4.5
v0.4.4
v0.4.0
v0.3.0
v0.2.2
v.0.2.1-8
v.0.2.1-5
v.0.2.1-4
v.0.2.1-3
v.0.2.1-2
v.0.2.0
v.0.1.6
v.0.1.5
v.0.1.4
v.0.1.2
v.0.1.1
v.0.1.0
Fixed in
1.11.0
References
Updated Jun 10, 2026 · Source: OSV.dev
CVE-2023-47116
GHSA-p59w-9gqw-wj8r
PYSEC-2024-127
Jan 31, 2024
Label Studio SSRF on Import Bypassing `SSRF_PROTECTION_ENABLED` Protections
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
IntroductionThis write-up describes a vulnerability found in Label Studio, a popular open source data labeling tool. The vulnerability affects all versions of Label Studio prior to OverviewLabel Studio's SSRF protections that can be enabled by setting the DescriptionThe following
The
The issue here is the SSRF validation is only performed before the request is sent, and does not validate the destination IP address. Therefore, an attacker can either redirect the request or perform a DNS rebinding attack to bypass this protection. Proof of ConceptBoth the HTTP redirection and DNS rebinding methods for bypassing Label Studio's SSRF protections are explained below. HTTP RedirectionThe python
DNS Rebinding AttackDNS rebinding can bypass SSRF protections by resolving to an external IP address for the first resolution, but when the request is sent resolves to an internal IP address that is blocked. For an example, the domain ImpactSSRF vulnerabilities pose a significant risk on cloud environments, since instance credentials are managed by internal web APIs. An attacker can bypass Label Studio's SSRF protections to access internal web servers and partially compromise the confidentiality of those internal servers. Remediation Advice
Discovered
Affected versions
0.4.1
0.4.2
0.4.3
0.4.4
0.4.4.post1
0.4.4.post2
0.4.5
0.4.6
0.4.6.post1
0.4.6.post2
0.4.7
0.4.8
+ 67 more Show less
0.5.0
0.5.1
0.6.0
0.6.1
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.4.post0
0.7.4.post1
0.7.5.post1
0.7.5.post2
0.8.0
0.8.0.post0
0.8.1
0.8.1.post0
0.8.2
0.8.2.post0
0.9.0
0.9.0.post2
0.9.0.post3
0.9.0.post4
0.9.0.post5
0.9.1
0.9.1.post0
0.9.1.post1
0.9.1.post2
1.0.0
1.0.0.post0
1.0.0.post1
1.0.0.post2
1.0.0.post3
1.0.1
1.0.2
1.0.2.post0
1.1.0
1.1.0rc0
1.1.1
1.10.0
1.10.0.post0
1.10.1
1.2
1.3
1.3.post0
1.3.post1
1.4
1.4.1
1.4.1.post0
1.4.1.post1
1.5.0
1.5.0.post0
1.6.0
1.7.0
1.7.1
1.7.2
1.7.3
1.8.0
1.8.1
1.8.2
1.8.2.post0
1.8.2.post1
1.9.0
1.9.1
1.9.1.post0
1.9.2
1.9.2.post0
Fixed in
1.11.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-23633
GHSA-fq23-g58m-799r
PYSEC-2024-128
Jan 24, 2024
Cross-site Scripting Vulnerability on Data Import
4.7
/ 10
Medium
Network
Low
None
Required
Changed
Low
None
None
IntroductionThis write-up describes a vulnerability found in Label Studio, a popular open source data labeling tool. The vulnerability affects all versions of Label Studio prior to OverviewLabel Studio had a remote import feature allowed users to import data from a remote web source, that was downloaded and could be viewed on the website. This feature could had been abused to download a HTML file that executed malicious JavaScript code in the context of the Label Studio website. DescriptionThe following code snippet in Label Studio showed that is a URL passed the SSRF verification checks, the contents of the file would be downloaded using the filename in the URL.
The downloaded file path could then be retrieved by sending a request to
Since the Proof of ConceptBelow were the steps to recreate this issue:
ImpactExecuting arbitrary JavaScript could result in an attacker performing malicious actions on Label Studio users if they visit the crafted avatar image. For an example, an attacker can craft a JavaScript payload that adds a new Django Super Administrator user if a Django administrator visits the image. Remediation Advice
Discovered
Affected versions
0.4.1
0.4.2
0.4.3
0.4.4
0.4.4.post1
0.4.4.post2
0.4.5
0.4.6
0.4.6.post1
0.4.6.post2
0.4.7
0.4.8
+ 66 more Show less
0.5.0
0.5.1
0.6.0
0.6.1
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.4.post0
0.7.4.post1
0.7.5.post1
0.7.5.post2
0.8.0
0.8.0.post0
0.8.1
0.8.1.post0
0.8.2
0.8.2.post0
0.9.0
0.9.0.post2
0.9.0.post3
0.9.0.post4
0.9.0.post5
0.9.1
0.9.1.post0
0.9.1.post1
0.9.1.post2
1.0.0
1.0.0.post0
1.0.0.post1
1.0.0.post2
1.0.0.post3
1.0.1
1.0.2
1.0.2.post0
1.1.0
1.1.0rc0
1.1.1
1.10.0
1.10.0.post0
1.2
1.3
1.3.post0
1.3.post1
1.4
1.4.1
1.4.1.post0
1.4.1.post1
1.5.0
1.5.0.post0
1.6.0
1.7.0
1.7.1
1.7.2
1.7.3
1.8.0
1.8.1
1.8.2
1.8.2.post0
1.8.2.post1
1.9.0
1.9.1
1.9.1.post0
1.9.2
1.9.2.post0
Fixed in
1.10.1
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2023-47117
GHSA-6hjj-gq77-j4qw
PYSEC-2023-275
Nov 14, 2023
Label Studio Object Relational Mapper Leak Vulnerability in Filtering Task
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
IntroductionThis write-up describes a vulnerability found in Label Studio, a popular open source data labeling tool. The vulnerability affects all versions of Label Studio prior to OverviewIn all current versions of Label Studio, the application allows users to insecurely set filters for filtering tasks. An attacker can construct a filter chain to filter tasks based on sensitive fields for all user accounts on the platform by exploiting Django's Object Relational Mapper (ORM). Since the results of query can be manipulated by the ORM filter, an attacker can leak these sensitive fields character by character. For an example, the following filter chain will task results by the password hash of an account on Label Studio.
For consistency, this type of vulnerability will be termed as ORM Leak in the rest of this disclosure. In addition, Label Studio had a hard coded secret key that an attacker can use to forge a session token of any user by exploiting this ORM Leak vulnerability to leak account password hashes. DescriptionThe following code snippet from the
These
The
The following code snippet of the
Finally, the
Proof of ConceptBelow are the steps to exploit about how to exploit this vulnerability to leak the password hash of an account on Label Studio.
The following example GIF demonstrates exploiting this ORM Leak vulnerability to retrieve the password hash
ImpactThis vulnerability can be exploited to completely compromise the confidentiality of highly sensitive account information, such as account password hashes. For all versions Remediation Advice
Discovered
| ||
1.9.1.post0
pre
9 CVEs
CVE-2026-22033
PYSEC-2026-1502
GHSA-2mq9-hm29-8qch
Jul 07, 2026
Label Studio is vulnerable to full account takeover by chaining Stored XSS + IDOR in User Profile via custom_hotkeys field
Critical
Network
Low
Low
None
PrologueThese vulnerabilities have been found and chained by DCODX-AI. Validation of the exploit chain has been confirmed manually. SummaryA persistent stored cross-site scripting (XSS) vulnerability exists in the custom_hotkeys functionality of the application. An authenticated attacker (or one who can trick a user/administrator into updating their custom_hotkeys) can inject JavaScript code that executes in other users’ browsers when those users load any page using the DetailsWithin
Here, user.custom_hotkeys is run through json_dumps_ensure_ascii (in In
The serializer allows
When another user loads a page using templates/base.html (for example PoC
Example request
Example response
ImpactExploitation impact:
Who is impacted:
Affected versions
0.4.1
0.4.2
0.4.3
0.4.4
0.4.4.post1
0.4.4.post2
0.4.5
0.4.6
0.4.6.post1
0.4.6.post2
0.4.7
0.4.8
+ 83 more Show less
0.5.0
0.5.1
0.6.0
0.6.1
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.4.post0
0.7.4.post1
0.7.5.post1
0.7.5.post2
0.8.0
0.8.0.post0
0.8.1
0.8.1.post0
0.8.2
0.8.2.post0
0.9.0
0.9.0.post2
0.9.0.post3
0.9.0.post4
0.9.0.post5
0.9.1
0.9.1.post0
0.9.1.post1
0.9.1.post2
1.0.0
1.0.0.post0
1.0.0.post1
1.0.0.post2
1.0.0.post3
1.0.1
1.0.2
1.0.2.post0
1.1.0
1.1.0rc0
1.1.1
1.10.0
1.10.0.post0
1.10.1
1.11.0
1.12.0
1.12.0.post0
1.12.1
1.13.0
1.13.1
1.14.0
1.14.0.post0
1.15.0
1.16.0
1.17.0
1.18.0
1.19.0
1.2
1.20.0
1.21.0
1.22.0
1.3
1.3.post0
1.3.post1
1.4
1.4.1
1.4.1.post0
1.4.1.post1
1.5.0
1.5.0.post0
1.6.0
1.7.0
1.7.1
1.7.2
1.7.3
1.8.0
1.8.1
1.8.2
1.8.2.post0
1.8.2.post1
1.9.0
1.9.1
1.9.1.post0
1.9.2
1.9.2.post0
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-25297
PYSEC-2026-1503
GHSA-m238-fmcw-wh58
Jul 07, 2026
Label Studio allows Server-Side Request Forgery in the S3 Storage Endpoint
8.6
/ 10
High
Network
Low
None
None
Changed
High
None
None
DescriptionLabel Studio's S3 storage integration feature contains a Server-Side Request Forgery (SSRF) vulnerability in its endpoint configuration. When creating an S3 storage connection, the application allows users to specify a custom S3 endpoint URL via the s3_endpoint parameter. This endpoint URL is passed directly to the boto3 AWS SDK without proper validation or restrictions on the protocol or destination. The vulnerability allows an attacker to make the application send HTTP requests to arbitrary internal services by specifying them as the S3 endpoint. When the storage sync operation is triggered, the application attempts to make S3 API calls to the specified endpoint, effectively making HTTP requests to the target service and returning the response in error messages. This SSRF vulnerability enables attackers to bypass network segmentation and access internal services that should not be accessible from the external network. The vulnerability is particularly severe because error messages from failed requests contain the full response body, allowing data exfiltration from internal services. Steps to reproduce
The application will attempt to connect to the specified endpoint URL as if it were an S3 service. When the request fails due to invalid S3 API responses, the error message will contain the raw response from the internal service, allowing access to internal resources. Mitigations
ImpactThis vulnerability has high severity as it allows authenticated users to make requests to arbitrary internal services from the application server, potentially exposing sensitive internal resources and bypassing network segmentation. The inclusion of response data in error messages makes this particularly effective for data exfiltration. Affected versions
0.4.1
0.4.2
0.4.3
0.4.4
0.4.4.post1
0.4.4.post2
0.4.5
0.4.6
0.4.6.post1
0.4.6.post2
0.4.7
0.4.8
+ 76 more Show less
0.5.0
0.5.1
0.6.0
0.6.1
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.4.post0
0.7.4.post1
0.7.5.post1
0.7.5.post2
0.8.0
0.8.0.post0
0.8.1
0.8.1.post0
0.8.2
0.8.2.post0
0.9.0
0.9.0.post2
0.9.0.post3
0.9.0.post4
0.9.0.post5
0.9.1
0.9.1.post0
0.9.1.post1
0.9.1.post2
1.0.0
1.0.0.post0
1.0.0.post1
1.0.0.post2
1.0.0.post3
1.0.1
1.0.2
1.0.2.post0
1.1.0
1.1.0rc0
1.1.1
1.10.0
1.10.0.post0
1.10.1
1.11.0
1.12.0
1.12.0.post0
1.12.1
1.13.0
1.13.1
1.14.0
1.14.0.post0
1.15.0
1.2
1.3
1.3.post0
1.3.post1
1.4
1.4.1
1.4.1.post0
1.4.1.post1
1.5.0
1.5.0.post0
1.6.0
1.7.0
1.7.1
1.7.2
1.7.3
1.8.0
1.8.1
1.8.2
1.8.2.post0
1.8.2.post1
1.9.0
1.9.1
1.9.1.post0
1.9.2
1.9.2.post0
Fixed in
1.16.0
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-25296
PYSEC-2026-1504
GHSA-wpq5-3366-mqw4
Jul 07, 2026
Label Studio allows Cross-Site Scripting (XSS) via GET request to `/projects/upload-example` endpoint
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
DescriptionLabel Studio's The vulnerability exists because the upload-example endpoint renders user-provided HTML content without proper sanitization on a GET request. This allows attackers to inject and execute arbitrary JavaScript in victims' browsers by getting them to visit a maliciously crafted URL. This is considered vulnerable because it enables attackers to execute JavaScript in victims' contexts, potentially allowing theft of sensitive data, session hijacking, or other malicious actions. Steps to reproduce
When executed, the payload causes the application to render an HTML page containing an img tag that fails to load, triggering the onerror event handler which executes base64-decoded JavaScript, demonstrating successful XSS execution in the victim's browser. Mitigations
ImpactThe vulnerability requires no special privileges and can be exploited by getting a victim to visit a crafted URL. The impact is high as it allows arbitrary JavaScript execution in victims' browsers, potentially exposing sensitive data or enabling account takeover through session theft. Affected versions
0.4.1
0.4.2
0.4.3
0.4.4
0.4.4.post1
0.4.4.post2
0.4.5
0.4.6
0.4.6.post1
0.4.6.post2
0.4.7
0.4.8
+ 76 more Show less
0.5.0
0.5.1
0.6.0
0.6.1
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.4.post0
0.7.4.post1
0.7.5.post1
0.7.5.post2
0.8.0
0.8.0.post0
0.8.1
0.8.1.post0
0.8.2
0.8.2.post0
0.9.0
0.9.0.post2
0.9.0.post3
0.9.0.post4
0.9.0.post5
0.9.1
0.9.1.post0
0.9.1.post1
0.9.1.post2
1.0.0
1.0.0.post0
1.0.0.post1
1.0.0.post2
1.0.0.post3
1.0.1
1.0.2
1.0.2.post0
1.1.0
1.1.0rc0
1.1.1
1.10.0
1.10.0.post0
1.10.1
1.11.0
1.12.0
1.12.0.post0
1.12.1
1.13.0
1.13.1
1.14.0
1.14.0.post0
1.15.0
1.2
1.3
1.3.post0
1.3.post1
1.4
1.4.1
1.4.1.post0
1.4.1.post1
1.5.0
1.5.0.post0
1.6.0
1.7.0
1.7.1
1.7.2
1.7.3
1.8.0
1.8.1
1.8.2
1.8.2.post0
1.8.2.post1
1.9.0
1.9.1
1.9.1.post0
1.9.2
1.9.2.post0
Fixed in
1.16.0
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-47783
GHSA-8jhr-wpcm-hh4h
PYSEC-2025-124
May 15, 2025
label-studio vulnerable to Cross-Site Scripting (Reflected) via the label_config parameter.
High
Network
Low
None
SummaryThe vulnerability allows an attacker to inject a malicious script into the context of a web page, which can lead to data theft, unauthorized actions on behalf of the user, and other attacks. DetailsThe vulnerability is reproducible when sending a properly formatted request to the
The vulnerability is specifically located in line 57, where HttpResponse is used.
PoCSend the following request after changing the
Or you can create a vulnerable HTML page by changing
Impact
Affected versions
0.4.1
0.4.2
0.4.3
0.4.4
0.4.4.post1
0.4.4.post2
0.4.5
0.4.6
0.4.6.post1
0.4.6.post2
0.4.7
0.4.8
+ 78 more Show less
0.5.0
0.5.1
0.6.0
0.6.1
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.4.post0
0.7.4.post1
0.7.5.post1
0.7.5.post2
0.8.0
0.8.0.post0
0.8.1
0.8.1.post0
0.8.2
0.8.2.post0
0.9.0
0.9.0.post2
0.9.0.post3
0.9.0.post4
0.9.0.post5
0.9.1
0.9.1.post0
0.9.1.post1
0.9.1.post2
1.0.0
1.0.0.post0
1.0.0.post1
1.0.0.post2
1.0.0.post3
1.0.1
1.0.2
1.0.2.post0
1.1.0
1.1.0rc0
1.1.1
1.10.0
1.10.0.post0
1.10.1
1.11.0
1.12.0
1.12.0.post0
1.12.1
1.13.0
1.13.1
1.14.0
1.14.0.post0
1.15.0
1.16.0
1.17.0
1.2
1.3
1.3.post0
1.3.post1
1.4
1.4.1
1.4.1.post0
1.4.1.post1
1.5.0
1.5.0.post0
1.6.0
1.7.0
1.7.1
1.7.2
1.7.3
1.8.0
1.8.1
1.8.2
1.8.2.post0
1.8.2.post1
1.9.0
1.9.1
1.9.1.post0
1.9.2
1.9.2.post0
Fixed in
1.18.0
References
Updated Jun 06, 2026 · Source: OSV.dev
CVE-2024-26152
PYSEC-2024-249
GHSA-6xv9-957j-qfhg
Feb 22, 2024
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
SummaryOn all Label Studio versions prior to 1.11.0, data imported via file upload feature is not properly sanitized prior to being rendered within a DetailsNeed permission to use the "data import" function. This was reproduced on Label Studio 1.10.1. PoC
The following are the contents of the files used in the PoC
ImpactMalicious scripts can be injected into the code, and when linked with vulnerabilities such as CSRF, it can cause even greater damage. In particular, It can become a source of further attacks, especially when linked to social engineering. Affected versions
0.4.1
0.4.2
0.4.3
0.4.4
0.4.4.post1
0.4.4.post2
0.4.5
0.4.6
0.4.6.post1
0.4.6.post2
0.4.7
0.4.8
+ 113 more Show less
0.5.0
0.5.1
0.6.0
0.6.1
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.4.post0
0.7.4.post1
0.7.5.post1
0.7.5.post2
0.8.0
0.8.0.post0
0.8.1
0.8.1.post0
0.8.2
0.8.2.post0
0.9.0
0.9.0.post2
0.9.0.post3
0.9.0.post4
0.9.0.post5
0.9.1
0.9.1.post0
0.9.1.post1
0.9.1.post2
1.0.0
1.0.0.post0
1.0.0.post1
1.0.0.post2
1.0.0.post3
1.0.1
1.0.2
1.0.2.post0
1.1.0
1.1.0rc0
1.1.1
1.10.0
1.10.0.post0
1.10.1
1.2
1.3
1.3.post0
1.3.post1
1.4
1.4.1
1.4.1.post0
1.4.1.post1
1.5.0
1.5.0.post0
1.6.0
1.7.0
1.7.1
1.7.2
1.7.3
1.8.0
1.8.1
1.8.2
1.8.2.post0
1.8.2.post1
1.9.0
1.9.1
1.9.1.post0
1.9.2
1.9.2.post0
v1.4.1
v1.4.0
v1.3.0
v1.2.0
v1.1.1
v1.1.0
v1.0.2
v1.0.1
v1.0.0
v0.9.1.post1
v0.9.1.post0
v0.9.0.post5
v0.9.0.post4
v0.9.0.post3
v0.9.0
v0.8.2
v0.8.1
v0.8.0
v0.7.5.post0
v0.7.3
v0.7.2
v0.7.1
v0.7.0
v0.6.1
v0.6.0
v0.5.1
v0.4.8
v0.4.7
v0.4.6
v0.4.5
v0.4.4
v0.4.0
v0.3.0
v0.2.2
v.0.2.1-8
v.0.2.1-5
v.0.2.1-4
v.0.2.1-3
v.0.2.1-2
v.0.2.0
v.0.1.6
v.0.1.5
v.0.1.4
v.0.1.2
v.0.1.1
v.0.1.0
Fixed in
1.11.0
References
Updated Jun 10, 2026 · Source: OSV.dev
CVE-2023-47116
GHSA-p59w-9gqw-wj8r
PYSEC-2024-127
Jan 31, 2024
Label Studio SSRF on Import Bypassing `SSRF_PROTECTION_ENABLED` Protections
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
IntroductionThis write-up describes a vulnerability found in Label Studio, a popular open source data labeling tool. The vulnerability affects all versions of Label Studio prior to OverviewLabel Studio's SSRF protections that can be enabled by setting the DescriptionThe following
The
The issue here is the SSRF validation is only performed before the request is sent, and does not validate the destination IP address. Therefore, an attacker can either redirect the request or perform a DNS rebinding attack to bypass this protection. Proof of ConceptBoth the HTTP redirection and DNS rebinding methods for bypassing Label Studio's SSRF protections are explained below. HTTP RedirectionThe python
DNS Rebinding AttackDNS rebinding can bypass SSRF protections by resolving to an external IP address for the first resolution, but when the request is sent resolves to an internal IP address that is blocked. For an example, the domain ImpactSSRF vulnerabilities pose a significant risk on cloud environments, since instance credentials are managed by internal web APIs. An attacker can bypass Label Studio's SSRF protections to access internal web servers and partially compromise the confidentiality of those internal servers. Remediation Advice
Discovered
Affected versions
0.4.1
0.4.2
0.4.3
0.4.4
0.4.4.post1
0.4.4.post2
0.4.5
0.4.6
0.4.6.post1
0.4.6.post2
0.4.7
0.4.8
+ 67 more Show less
0.5.0
0.5.1
0.6.0
0.6.1
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.4.post0
0.7.4.post1
0.7.5.post1
0.7.5.post2
0.8.0
0.8.0.post0
0.8.1
0.8.1.post0
0.8.2
0.8.2.post0
0.9.0
0.9.0.post2
0.9.0.post3
0.9.0.post4
0.9.0.post5
0.9.1
0.9.1.post0
0.9.1.post1
0.9.1.post2
1.0.0
1.0.0.post0
1.0.0.post1
1.0.0.post2
1.0.0.post3
1.0.1
1.0.2
1.0.2.post0
1.1.0
1.1.0rc0
1.1.1
1.10.0
1.10.0.post0
1.10.1
1.2
1.3
1.3.post0
1.3.post1
1.4
1.4.1
1.4.1.post0
1.4.1.post1
1.5.0
1.5.0.post0
1.6.0
1.7.0
1.7.1
1.7.2
1.7.3
1.8.0
1.8.1
1.8.2
1.8.2.post0
1.8.2.post1
1.9.0
1.9.1
1.9.1.post0
1.9.2
1.9.2.post0
Fixed in
1.11.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-23633
GHSA-fq23-g58m-799r
PYSEC-2024-128
Jan 24, 2024
Cross-site Scripting Vulnerability on Data Import
4.7
/ 10
Medium
Network
Low
None
Required
Changed
Low
None
None
IntroductionThis write-up describes a vulnerability found in Label Studio, a popular open source data labeling tool. The vulnerability affects all versions of Label Studio prior to OverviewLabel Studio had a remote import feature allowed users to import data from a remote web source, that was downloaded and could be viewed on the website. This feature could had been abused to download a HTML file that executed malicious JavaScript code in the context of the Label Studio website. DescriptionThe following code snippet in Label Studio showed that is a URL passed the SSRF verification checks, the contents of the file would be downloaded using the filename in the URL.
The downloaded file path could then be retrieved by sending a request to
Since the Proof of ConceptBelow were the steps to recreate this issue:
ImpactExecuting arbitrary JavaScript could result in an attacker performing malicious actions on Label Studio users if they visit the crafted avatar image. For an example, an attacker can craft a JavaScript payload that adds a new Django Super Administrator user if a Django administrator visits the image. Remediation Advice
Discovered
Affected versions
0.4.1
0.4.2
0.4.3
0.4.4
0.4.4.post1
0.4.4.post2
0.4.5
0.4.6
0.4.6.post1
0.4.6.post2
0.4.7
0.4.8
+ 66 more Show less
0.5.0
0.5.1
0.6.0
0.6.1
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.4.post0
0.7.4.post1
0.7.5.post1
0.7.5.post2
0.8.0
0.8.0.post0
0.8.1
0.8.1.post0
0.8.2
0.8.2.post0
0.9.0
0.9.0.post2
0.9.0.post3
0.9.0.post4
0.9.0.post5
0.9.1
0.9.1.post0
0.9.1.post1
0.9.1.post2
1.0.0
1.0.0.post0
1.0.0.post1
1.0.0.post2
1.0.0.post3
1.0.1
1.0.2
1.0.2.post0
1.1.0
1.1.0rc0
1.1.1
1.10.0
1.10.0.post0
1.2
1.3
1.3.post0
1.3.post1
1.4
1.4.1
1.4.1.post0
1.4.1.post1
1.5.0
1.5.0.post0
1.6.0
1.7.0
1.7.1
1.7.2
1.7.3
1.8.0
1.8.1
1.8.2
1.8.2.post0
1.8.2.post1
1.9.0
1.9.1
1.9.1.post0
1.9.2
1.9.2.post0
Fixed in
1.10.1
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2023-47115
GHSA-q68h-xwq5-mm7x
PYSEC-2024-126
Jan 24, 2024
Cross-site Scripting Vulnerability on Avatar Upload
7.1
/ 10
High
Network
Low
None
Required
Changed
Low
Low
Low
IntroductionThis write-up describes a vulnerability found in Label Studio, a popular open source data labeling tool. The vulnerability affects all versions of Label Studio prior to OverviewLabel Studio has a cross-site scripting (XSS) vulnerability that could be exploited when an authenticated user uploads a crafted image file for their avatar that gets rendered as a HTML file on the website. DescriptionThe following code snippet in Label Studio shows that the only verification check is that the file is an image by extracting the dimensions from the file.
Label Studio serves avatar images using Django's built-in
The issue with the Django Proof of ConceptBelow are the steps to reproduce this issue and execute JavaScript code in the context of the Label Studio website.
ImpactExecuting arbitrary JavaScript could result in an attacker performing malicious actions on Label Studio users if they visit the crafted avatar image. For an example, an attacker can craft a JavaScript payload that adds a new Django Super Administrator user if a Django administrator visits the image. Remediation Advice
Discovered
Affected versions
0.4.1
0.4.2
0.4.3
0.4.4
0.4.4.post1
0.4.4.post2
0.4.5
0.4.6
0.4.6.post1
0.4.6.post2
0.4.7
0.4.8
+ 62 more Show less
0.5.0
0.5.1
0.6.0
0.6.1
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.4.post0
0.7.4.post1
0.7.5.post1
0.7.5.post2
0.8.0
0.8.0.post0
0.8.1
0.8.1.post0
0.8.2
0.8.2.post0
0.9.0
0.9.0.post2
0.9.0.post3
0.9.0.post4
0.9.0.post5
0.9.1
0.9.1.post0
0.9.1.post1
0.9.1.post2
1.0.0
1.0.0.post0
1.0.0.post1
1.0.0.post2
1.0.0.post3
1.0.1
1.0.2
1.0.2.post0
1.1.0
1.1.0rc0
1.1.1
1.2
1.3
1.3.post0
1.3.post1
1.4
1.4.1
1.4.1.post0
1.4.1.post1
1.5.0
1.5.0.post0
1.6.0
1.7.0
1.7.1
1.7.2
1.7.3
1.8.0
1.8.1
1.8.2
1.8.2.post0
1.8.2.post1
1.9.0
1.9.1
1.9.1.post0
Fixed in
1.9.2
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2023-47117
GHSA-6hjj-gq77-j4qw
PYSEC-2023-275
Nov 14, 2023
Label Studio Object Relational Mapper Leak Vulnerability in Filtering Task
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
IntroductionThis write-up describes a vulnerability found in Label Studio, a popular open source data labeling tool. The vulnerability affects all versions of Label Studio prior to OverviewIn all current versions of Label Studio, the application allows users to insecurely set filters for filtering tasks. An attacker can construct a filter chain to filter tasks based on sensitive fields for all user accounts on the platform by exploiting Django's Object Relational Mapper (ORM). Since the results of query can be manipulated by the ORM filter, an attacker can leak these sensitive fields character by character. For an example, the following filter chain will task results by the password hash of an account on Label Studio.
For consistency, this type of vulnerability will be termed as ORM Leak in the rest of this disclosure. In addition, Label Studio had a hard coded secret key that an attacker can use to forge a session token of any user by exploiting this ORM Leak vulnerability to leak account password hashes. DescriptionThe following code snippet from the
These
The
The following code snippet of the
Finally, the
Proof of ConceptBelow are the steps to exploit about how to exploit this vulnerability to leak the password hash of an account on Label Studio.
The following example GIF demonstrates exploiting this ORM Leak vulnerability to retrieve the password hash
ImpactThis vulnerability can be exploited to completely compromise the confidentiality of highly sensitive account information, such as account password hashes. For all versions Remediation Advice
Discovered
| ||
1.9.1
patch
9 CVEs
CVE-2026-22033
PYSEC-2026-1502
GHSA-2mq9-hm29-8qch
Jul 07, 2026
Label Studio is vulnerable to full account takeover by chaining Stored XSS + IDOR in User Profile via custom_hotkeys field
Critical
Network
Low
Low
None
PrologueThese vulnerabilities have been found and chained by DCODX-AI. Validation of the exploit chain has been confirmed manually. SummaryA persistent stored cross-site scripting (XSS) vulnerability exists in the custom_hotkeys functionality of the application. An authenticated attacker (or one who can trick a user/administrator into updating their custom_hotkeys) can inject JavaScript code that executes in other users’ browsers when those users load any page using the DetailsWithin
Here, user.custom_hotkeys is run through json_dumps_ensure_ascii (in In
The serializer allows
When another user loads a page using templates/base.html (for example PoC
Example request
Example response
ImpactExploitation impact:
Who is impacted:
Affected versions
0.4.1
0.4.2
0.4.3
0.4.4
0.4.4.post1
0.4.4.post2
0.4.5
0.4.6
0.4.6.post1
0.4.6.post2
0.4.7
0.4.8
+ 83 more Show less
0.5.0
0.5.1
0.6.0
0.6.1
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.4.post0
0.7.4.post1
0.7.5.post1
0.7.5.post2
0.8.0
0.8.0.post0
0.8.1
0.8.1.post0
0.8.2
0.8.2.post0
0.9.0
0.9.0.post2
0.9.0.post3
0.9.0.post4
0.9.0.post5
0.9.1
0.9.1.post0
0.9.1.post1
0.9.1.post2
1.0.0
1.0.0.post0
1.0.0.post1
1.0.0.post2
1.0.0.post3
1.0.1
1.0.2
1.0.2.post0
1.1.0
1.1.0rc0
1.1.1
1.10.0
1.10.0.post0
1.10.1
1.11.0
1.12.0
1.12.0.post0
1.12.1
1.13.0
1.13.1
1.14.0
1.14.0.post0
1.15.0
1.16.0
1.17.0
1.18.0
1.19.0
1.2
1.20.0
1.21.0
1.22.0
1.3
1.3.post0
1.3.post1
1.4
1.4.1
1.4.1.post0
1.4.1.post1
1.5.0
1.5.0.post0
1.6.0
1.7.0
1.7.1
1.7.2
1.7.3
1.8.0
1.8.1
1.8.2
1.8.2.post0
1.8.2.post1
1.9.0
1.9.1
1.9.1.post0
1.9.2
1.9.2.post0
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-25297
PYSEC-2026-1503
GHSA-m238-fmcw-wh58
Jul 07, 2026
Label Studio allows Server-Side Request Forgery in the S3 Storage Endpoint
8.6
/ 10
High
Network
Low
None
None
Changed
High
None
None
DescriptionLabel Studio's S3 storage integration feature contains a Server-Side Request Forgery (SSRF) vulnerability in its endpoint configuration. When creating an S3 storage connection, the application allows users to specify a custom S3 endpoint URL via the s3_endpoint parameter. This endpoint URL is passed directly to the boto3 AWS SDK without proper validation or restrictions on the protocol or destination. The vulnerability allows an attacker to make the application send HTTP requests to arbitrary internal services by specifying them as the S3 endpoint. When the storage sync operation is triggered, the application attempts to make S3 API calls to the specified endpoint, effectively making HTTP requests to the target service and returning the response in error messages. This SSRF vulnerability enables attackers to bypass network segmentation and access internal services that should not be accessible from the external network. The vulnerability is particularly severe because error messages from failed requests contain the full response body, allowing data exfiltration from internal services. Steps to reproduce
The application will attempt to connect to the specified endpoint URL as if it were an S3 service. When the request fails due to invalid S3 API responses, the error message will contain the raw response from the internal service, allowing access to internal resources. Mitigations
ImpactThis vulnerability has high severity as it allows authenticated users to make requests to arbitrary internal services from the application server, potentially exposing sensitive internal resources and bypassing network segmentation. The inclusion of response data in error messages makes this particularly effective for data exfiltration. Affected versions
0.4.1
0.4.2
0.4.3
0.4.4
0.4.4.post1
0.4.4.post2
0.4.5
0.4.6
0.4.6.post1
0.4.6.post2
0.4.7
0.4.8
+ 76 more Show less
0.5.0
0.5.1
0.6.0
0.6.1
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.4.post0
0.7.4.post1
0.7.5.post1
0.7.5.post2
0.8.0
0.8.0.post0
0.8.1
0.8.1.post0
0.8.2
0.8.2.post0
0.9.0
0.9.0.post2
0.9.0.post3
0.9.0.post4
0.9.0.post5
0.9.1
0.9.1.post0
0.9.1.post1
0.9.1.post2
1.0.0
1.0.0.post0
1.0.0.post1
1.0.0.post2
1.0.0.post3
1.0.1
1.0.2
1.0.2.post0
1.1.0
1.1.0rc0
1.1.1
1.10.0
1.10.0.post0
1.10.1
1.11.0
1.12.0
1.12.0.post0
1.12.1
1.13.0
1.13.1
1.14.0
1.14.0.post0
1.15.0
1.2
1.3
1.3.post0
1.3.post1
1.4
1.4.1
1.4.1.post0
1.4.1.post1
1.5.0
1.5.0.post0
1.6.0
1.7.0
1.7.1
1.7.2
1.7.3
1.8.0
1.8.1
1.8.2
1.8.2.post0
1.8.2.post1
1.9.0
1.9.1
1.9.1.post0
1.9.2
1.9.2.post0
Fixed in
1.16.0
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-25296
PYSEC-2026-1504
GHSA-wpq5-3366-mqw4
Jul 07, 2026
Label Studio allows Cross-Site Scripting (XSS) via GET request to `/projects/upload-example` endpoint
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
DescriptionLabel Studio's The vulnerability exists because the upload-example endpoint renders user-provided HTML content without proper sanitization on a GET request. This allows attackers to inject and execute arbitrary JavaScript in victims' browsers by getting them to visit a maliciously crafted URL. This is considered vulnerable because it enables attackers to execute JavaScript in victims' contexts, potentially allowing theft of sensitive data, session hijacking, or other malicious actions. Steps to reproduce
When executed, the payload causes the application to render an HTML page containing an img tag that fails to load, triggering the onerror event handler which executes base64-decoded JavaScript, demonstrating successful XSS execution in the victim's browser. Mitigations
ImpactThe vulnerability requires no special privileges and can be exploited by getting a victim to visit a crafted URL. The impact is high as it allows arbitrary JavaScript execution in victims' browsers, potentially exposing sensitive data or enabling account takeover through session theft. Affected versions
0.4.1
0.4.2
0.4.3
0.4.4
0.4.4.post1
0.4.4.post2
0.4.5
0.4.6
0.4.6.post1
0.4.6.post2
0.4.7
0.4.8
+ 76 more Show less
0.5.0
0.5.1
0.6.0
0.6.1
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.4.post0
0.7.4.post1
0.7.5.post1
0.7.5.post2
0.8.0
0.8.0.post0
0.8.1
0.8.1.post0
0.8.2
0.8.2.post0
0.9.0
0.9.0.post2
0.9.0.post3
0.9.0.post4
0.9.0.post5
0.9.1
0.9.1.post0
0.9.1.post1
0.9.1.post2
1.0.0
1.0.0.post0
1.0.0.post1
1.0.0.post2
1.0.0.post3
1.0.1
1.0.2
1.0.2.post0
1.1.0
1.1.0rc0
1.1.1
1.10.0
1.10.0.post0
1.10.1
1.11.0
1.12.0
1.12.0.post0
1.12.1
1.13.0
1.13.1
1.14.0
1.14.0.post0
1.15.0
1.2
1.3
1.3.post0
1.3.post1
1.4
1.4.1
1.4.1.post0
1.4.1.post1
1.5.0
1.5.0.post0
1.6.0
1.7.0
1.7.1
1.7.2
1.7.3
1.8.0
1.8.1
1.8.2
1.8.2.post0
1.8.2.post1
1.9.0
1.9.1
1.9.1.post0
1.9.2
1.9.2.post0
Fixed in
1.16.0
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-47783
GHSA-8jhr-wpcm-hh4h
PYSEC-2025-124
May 15, 2025
label-studio vulnerable to Cross-Site Scripting (Reflected) via the label_config parameter.
High
Network
Low
None
SummaryThe vulnerability allows an attacker to inject a malicious script into the context of a web page, which can lead to data theft, unauthorized actions on behalf of the user, and other attacks. DetailsThe vulnerability is reproducible when sending a properly formatted request to the
The vulnerability is specifically located in line 57, where HttpResponse is used.
PoCSend the following request after changing the
Or you can create a vulnerable HTML page by changing
Impact
Affected versions
0.4.1
0.4.2
0.4.3
0.4.4
0.4.4.post1
0.4.4.post2
0.4.5
0.4.6
0.4.6.post1
0.4.6.post2
0.4.7
0.4.8
+ 78 more Show less
0.5.0
0.5.1
0.6.0
0.6.1
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.4.post0
0.7.4.post1
0.7.5.post1
0.7.5.post2
0.8.0
0.8.0.post0
0.8.1
0.8.1.post0
0.8.2
0.8.2.post0
0.9.0
0.9.0.post2
0.9.0.post3
0.9.0.post4
0.9.0.post5
0.9.1
0.9.1.post0
0.9.1.post1
0.9.1.post2
1.0.0
1.0.0.post0
1.0.0.post1
1.0.0.post2
1.0.0.post3
1.0.1
1.0.2
1.0.2.post0
1.1.0
1.1.0rc0
1.1.1
1.10.0
1.10.0.post0
1.10.1
1.11.0
1.12.0
1.12.0.post0
1.12.1
1.13.0
1.13.1
1.14.0
1.14.0.post0
1.15.0
1.16.0
1.17.0
1.2
1.3
1.3.post0
1.3.post1
1.4
1.4.1
1.4.1.post0
1.4.1.post1
1.5.0
1.5.0.post0
1.6.0
1.7.0
1.7.1
1.7.2
1.7.3
1.8.0
1.8.1
1.8.2
1.8.2.post0
1.8.2.post1
1.9.0
1.9.1
1.9.1.post0
1.9.2
1.9.2.post0
Fixed in
1.18.0
References
Updated Jun 06, 2026 · Source: OSV.dev
CVE-2024-26152
PYSEC-2024-249
GHSA-6xv9-957j-qfhg
Feb 22, 2024
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
SummaryOn all Label Studio versions prior to 1.11.0, data imported via file upload feature is not properly sanitized prior to being rendered within a DetailsNeed permission to use the "data import" function. This was reproduced on Label Studio 1.10.1. PoC
The following are the contents of the files used in the PoC
ImpactMalicious scripts can be injected into the code, and when linked with vulnerabilities such as CSRF, it can cause even greater damage. In particular, It can become a source of further attacks, especially when linked to social engineering. Affected versions
0.4.1
0.4.2
0.4.3
0.4.4
0.4.4.post1
0.4.4.post2
0.4.5
0.4.6
0.4.6.post1
0.4.6.post2
0.4.7
0.4.8
+ 113 more Show less
0.5.0
0.5.1
0.6.0
0.6.1
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.4.post0
0.7.4.post1
0.7.5.post1
0.7.5.post2
0.8.0
0.8.0.post0
0.8.1
0.8.1.post0
0.8.2
0.8.2.post0
0.9.0
0.9.0.post2
0.9.0.post3
0.9.0.post4
0.9.0.post5
0.9.1
0.9.1.post0
0.9.1.post1
0.9.1.post2
1.0.0
1.0.0.post0
1.0.0.post1
1.0.0.post2
1.0.0.post3
1.0.1
1.0.2
1.0.2.post0
1.1.0
1.1.0rc0
1.1.1
1.10.0
1.10.0.post0
1.10.1
1.2
1.3
1.3.post0
1.3.post1
1.4
1.4.1
1.4.1.post0
1.4.1.post1
1.5.0
1.5.0.post0
1.6.0
1.7.0
1.7.1
1.7.2
1.7.3
1.8.0
1.8.1
1.8.2
1.8.2.post0
1.8.2.post1
1.9.0
1.9.1
1.9.1.post0
1.9.2
1.9.2.post0
v1.4.1
v1.4.0
v1.3.0
v1.2.0
v1.1.1
v1.1.0
v1.0.2
v1.0.1
v1.0.0
v0.9.1.post1
v0.9.1.post0
v0.9.0.post5
v0.9.0.post4
v0.9.0.post3
v0.9.0
v0.8.2
v0.8.1
v0.8.0
v0.7.5.post0
v0.7.3
v0.7.2
v0.7.1
v0.7.0
v0.6.1
v0.6.0
v0.5.1
v0.4.8
v0.4.7
v0.4.6
v0.4.5
v0.4.4
v0.4.0
v0.3.0
v0.2.2
v.0.2.1-8
v.0.2.1-5
v.0.2.1-4
v.0.2.1-3
v.0.2.1-2
v.0.2.0
v.0.1.6
v.0.1.5
v.0.1.4
v.0.1.2
v.0.1.1
v.0.1.0
Fixed in
1.11.0
References
Updated Jun 10, 2026 · Source: OSV.dev
CVE-2023-47116
GHSA-p59w-9gqw-wj8r
PYSEC-2024-127
Jan 31, 2024
Label Studio SSRF on Import Bypassing `SSRF_PROTECTION_ENABLED` Protections
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
IntroductionThis write-up describes a vulnerability found in Label Studio, a popular open source data labeling tool. The vulnerability affects all versions of Label Studio prior to OverviewLabel Studio's SSRF protections that can be enabled by setting the DescriptionThe following
The
The issue here is the SSRF validation is only performed before the request is sent, and does not validate the destination IP address. Therefore, an attacker can either redirect the request or perform a DNS rebinding attack to bypass this protection. Proof of ConceptBoth the HTTP redirection and DNS rebinding methods for bypassing Label Studio's SSRF protections are explained below. HTTP RedirectionThe python
DNS Rebinding AttackDNS rebinding can bypass SSRF protections by resolving to an external IP address for the first resolution, but when the request is sent resolves to an internal IP address that is blocked. For an example, the domain ImpactSSRF vulnerabilities pose a significant risk on cloud environments, since instance credentials are managed by internal web APIs. An attacker can bypass Label Studio's SSRF protections to access internal web servers and partially compromise the confidentiality of those internal servers. Remediation Advice
Discovered
Affected versions
0.4.1
0.4.2
0.4.3
0.4.4
0.4.4.post1
0.4.4.post2
0.4.5
0.4.6
0.4.6.post1
0.4.6.post2
0.4.7
0.4.8
+ 67 more Show less
0.5.0
0.5.1
0.6.0
0.6.1
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.4.post0
0.7.4.post1
0.7.5.post1
0.7.5.post2
0.8.0
0.8.0.post0
0.8.1
0.8.1.post0
0.8.2
0.8.2.post0
0.9.0
0.9.0.post2
0.9.0.post3
0.9.0.post4
0.9.0.post5
0.9.1
0.9.1.post0
0.9.1.post1
0.9.1.post2
1.0.0
1.0.0.post0
1.0.0.post1
1.0.0.post2
1.0.0.post3
1.0.1
1.0.2
1.0.2.post0
1.1.0
1.1.0rc0
1.1.1
1.10.0
1.10.0.post0
1.10.1
1.2
1.3
1.3.post0
1.3.post1
1.4
1.4.1
1.4.1.post0
1.4.1.post1
1.5.0
1.5.0.post0
1.6.0
1.7.0
1.7.1
1.7.2
1.7.3
1.8.0
1.8.1
1.8.2
1.8.2.post0
1.8.2.post1
1.9.0
1.9.1
1.9.1.post0
1.9.2
1.9.2.post0
Fixed in
1.11.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-23633
GHSA-fq23-g58m-799r
PYSEC-2024-128
Jan 24, 2024
Cross-site Scripting Vulnerability on Data Import
4.7
/ 10
Medium
Network
Low
None
Required
Changed
Low
None
None
IntroductionThis write-up describes a vulnerability found in Label Studio, a popular open source data labeling tool. The vulnerability affects all versions of Label Studio prior to OverviewLabel Studio had a remote import feature allowed users to import data from a remote web source, that was downloaded and could be viewed on the website. This feature could had been abused to download a HTML file that executed malicious JavaScript code in the context of the Label Studio website. DescriptionThe following code snippet in Label Studio showed that is a URL passed the SSRF verification checks, the contents of the file would be downloaded using the filename in the URL.
The downloaded file path could then be retrieved by sending a request to
Since the Proof of ConceptBelow were the steps to recreate this issue:
ImpactExecuting arbitrary JavaScript could result in an attacker performing malicious actions on Label Studio users if they visit the crafted avatar image. For an example, an attacker can craft a JavaScript payload that adds a new Django Super Administrator user if a Django administrator visits the image. Remediation Advice
Discovered
Affected versions
0.4.1
0.4.2
0.4.3
0.4.4
0.4.4.post1
0.4.4.post2
0.4.5
0.4.6
0.4.6.post1
0.4.6.post2
0.4.7
0.4.8
+ 66 more Show less
0.5.0
0.5.1
0.6.0
0.6.1
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.4.post0
0.7.4.post1
0.7.5.post1
0.7.5.post2
0.8.0
0.8.0.post0
0.8.1
0.8.1.post0
0.8.2
0.8.2.post0
0.9.0
0.9.0.post2
0.9.0.post3
0.9.0.post4
0.9.0.post5
0.9.1
0.9.1.post0
0.9.1.post1
0.9.1.post2
1.0.0
1.0.0.post0
1.0.0.post1
1.0.0.post2
1.0.0.post3
1.0.1
1.0.2
1.0.2.post0
1.1.0
1.1.0rc0
1.1.1
1.10.0
1.10.0.post0
1.2
1.3
1.3.post0
1.3.post1
1.4
1.4.1
1.4.1.post0
1.4.1.post1
1.5.0
1.5.0.post0
1.6.0
1.7.0
1.7.1
1.7.2
1.7.3
1.8.0
1.8.1
1.8.2
1.8.2.post0
1.8.2.post1
1.9.0
1.9.1
1.9.1.post0
1.9.2
1.9.2.post0
Fixed in
1.10.1
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2023-47115
GHSA-q68h-xwq5-mm7x
PYSEC-2024-126
Jan 24, 2024
Cross-site Scripting Vulnerability on Avatar Upload
7.1
/ 10
High
Network
Low
None
Required
Changed
Low
Low
Low
IntroductionThis write-up describes a vulnerability found in Label Studio, a popular open source data labeling tool. The vulnerability affects all versions of Label Studio prior to OverviewLabel Studio has a cross-site scripting (XSS) vulnerability that could be exploited when an authenticated user uploads a crafted image file for their avatar that gets rendered as a HTML file on the website. DescriptionThe following code snippet in Label Studio shows that the only verification check is that the file is an image by extracting the dimensions from the file.
Label Studio serves avatar images using Django's built-in
The issue with the Django Proof of ConceptBelow are the steps to reproduce this issue and execute JavaScript code in the context of the Label Studio website.
ImpactExecuting arbitrary JavaScript could result in an attacker performing malicious actions on Label Studio users if they visit the crafted avatar image. For an example, an attacker can craft a JavaScript payload that adds a new Django Super Administrator user if a Django administrator visits the image. Remediation Advice
Discovered
Affected versions
0.4.1
0.4.2
0.4.3
0.4.4
0.4.4.post1
0.4.4.post2
0.4.5
0.4.6
0.4.6.post1
0.4.6.post2
0.4.7
0.4.8
+ 62 more Show less
0.5.0
0.5.1
0.6.0
0.6.1
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.4.post0
0.7.4.post1
0.7.5.post1
0.7.5.post2
0.8.0
0.8.0.post0
0.8.1
0.8.1.post0
0.8.2
0.8.2.post0
0.9.0
0.9.0.post2
0.9.0.post3
0.9.0.post4
0.9.0.post5
0.9.1
0.9.1.post0
0.9.1.post1
0.9.1.post2
1.0.0
1.0.0.post0
1.0.0.post1
1.0.0.post2
1.0.0.post3
1.0.1
1.0.2
1.0.2.post0
1.1.0
1.1.0rc0
1.1.1
1.2
1.3
1.3.post0
1.3.post1
1.4
1.4.1
1.4.1.post0
1.4.1.post1
1.5.0
1.5.0.post0
1.6.0
1.7.0
1.7.1
1.7.2
1.7.3
1.8.0
1.8.1
1.8.2
1.8.2.post0
1.8.2.post1
1.9.0
1.9.1
1.9.1.post0
Fixed in
1.9.2
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2023-47117
GHSA-6hjj-gq77-j4qw
PYSEC-2023-275
Nov 14, 2023
Label Studio Object Relational Mapper Leak Vulnerability in Filtering Task
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
IntroductionThis write-up describes a vulnerability found in Label Studio, a popular open source data labeling tool. The vulnerability affects all versions of Label Studio prior to OverviewIn all current versions of Label Studio, the application allows users to insecurely set filters for filtering tasks. An attacker can construct a filter chain to filter tasks based on sensitive fields for all user accounts on the platform by exploiting Django's Object Relational Mapper (ORM). Since the results of query can be manipulated by the ORM filter, an attacker can leak these sensitive fields character by character. For an example, the following filter chain will task results by the password hash of an account on Label Studio.
For consistency, this type of vulnerability will be termed as ORM Leak in the rest of this disclosure. In addition, Label Studio had a hard coded secret key that an attacker can use to forge a session token of any user by exploiting this ORM Leak vulnerability to leak account password hashes. DescriptionThe following code snippet from the
These
The
The following code snippet of the
Finally, the
Proof of ConceptBelow are the steps to exploit about how to exploit this vulnerability to leak the password hash of an account on Label Studio.
The following example GIF demonstrates exploiting this ORM Leak vulnerability to retrieve the password hash
ImpactThis vulnerability can be exploited to completely compromise the confidentiality of highly sensitive account information, such as account password hashes. For all versions Remediation Advice
Discovered
| ||
1.9.0
minor
9 CVEs
CVE-2026-22033
PYSEC-2026-1502
GHSA-2mq9-hm29-8qch
Jul 07, 2026
Label Studio is vulnerable to full account takeover by chaining Stored XSS + IDOR in User Profile via custom_hotkeys field
Critical
Network
Low
Low
None
PrologueThese vulnerabilities have been found and chained by DCODX-AI. Validation of the exploit chain has been confirmed manually. SummaryA persistent stored cross-site scripting (XSS) vulnerability exists in the custom_hotkeys functionality of the application. An authenticated attacker (or one who can trick a user/administrator into updating their custom_hotkeys) can inject JavaScript code that executes in other users’ browsers when those users load any page using the DetailsWithin
Here, user.custom_hotkeys is run through json_dumps_ensure_ascii (in In
The serializer allows
When another user loads a page using templates/base.html (for example PoC
Example request
Example response
ImpactExploitation impact:
Who is impacted:
Affected versions
0.4.1
0.4.2
0.4.3
0.4.4
0.4.4.post1
0.4.4.post2
0.4.5
0.4.6
0.4.6.post1
0.4.6.post2
0.4.7
0.4.8
+ 83 more Show less
0.5.0
0.5.1
0.6.0
0.6.1
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.4.post0
0.7.4.post1
0.7.5.post1
0.7.5.post2
0.8.0
0.8.0.post0
0.8.1
0.8.1.post0
0.8.2
0.8.2.post0
0.9.0
0.9.0.post2
0.9.0.post3
0.9.0.post4
0.9.0.post5
0.9.1
0.9.1.post0
0.9.1.post1
0.9.1.post2
1.0.0
1.0.0.post0
1.0.0.post1
1.0.0.post2
1.0.0.post3
1.0.1
1.0.2
1.0.2.post0
1.1.0
1.1.0rc0
1.1.1
1.10.0
1.10.0.post0
1.10.1
1.11.0
1.12.0
1.12.0.post0
1.12.1
1.13.0
1.13.1
1.14.0
1.14.0.post0
1.15.0
1.16.0
1.17.0
1.18.0
1.19.0
1.2
1.20.0
1.21.0
1.22.0
1.3
1.3.post0
1.3.post1
1.4
1.4.1
1.4.1.post0
1.4.1.post1
1.5.0
1.5.0.post0
1.6.0
1.7.0
1.7.1
1.7.2
1.7.3
1.8.0
1.8.1
1.8.2
1.8.2.post0
1.8.2.post1
1.9.0
1.9.1
1.9.1.post0
1.9.2
1.9.2.post0
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-25297
PYSEC-2026-1503
GHSA-m238-fmcw-wh58
Jul 07, 2026
Label Studio allows Server-Side Request Forgery in the S3 Storage Endpoint
8.6
/ 10
High
Network
Low
None
None
Changed
High
None
None
DescriptionLabel Studio's S3 storage integration feature contains a Server-Side Request Forgery (SSRF) vulnerability in its endpoint configuration. When creating an S3 storage connection, the application allows users to specify a custom S3 endpoint URL via the s3_endpoint parameter. This endpoint URL is passed directly to the boto3 AWS SDK without proper validation or restrictions on the protocol or destination. The vulnerability allows an attacker to make the application send HTTP requests to arbitrary internal services by specifying them as the S3 endpoint. When the storage sync operation is triggered, the application attempts to make S3 API calls to the specified endpoint, effectively making HTTP requests to the target service and returning the response in error messages. This SSRF vulnerability enables attackers to bypass network segmentation and access internal services that should not be accessible from the external network. The vulnerability is particularly severe because error messages from failed requests contain the full response body, allowing data exfiltration from internal services. Steps to reproduce
The application will attempt to connect to the specified endpoint URL as if it were an S3 service. When the request fails due to invalid S3 API responses, the error message will contain the raw response from the internal service, allowing access to internal resources. Mitigations
ImpactThis vulnerability has high severity as it allows authenticated users to make requests to arbitrary internal services from the application server, potentially exposing sensitive internal resources and bypassing network segmentation. The inclusion of response data in error messages makes this particularly effective for data exfiltration. Affected versions
0.4.1
0.4.2
0.4.3
0.4.4
0.4.4.post1
0.4.4.post2
0.4.5
0.4.6
0.4.6.post1
0.4.6.post2
0.4.7
0.4.8
+ 76 more Show less
0.5.0
0.5.1
0.6.0
0.6.1
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.4.post0
0.7.4.post1
0.7.5.post1
0.7.5.post2
0.8.0
0.8.0.post0
0.8.1
0.8.1.post0
0.8.2
0.8.2.post0
0.9.0
0.9.0.post2
0.9.0.post3
0.9.0.post4
0.9.0.post5
0.9.1
0.9.1.post0
0.9.1.post1
0.9.1.post2
1.0.0
1.0.0.post0
1.0.0.post1
1.0.0.post2
1.0.0.post3
1.0.1
1.0.2
1.0.2.post0
1.1.0
1.1.0rc0
1.1.1
1.10.0
1.10.0.post0
1.10.1
1.11.0
1.12.0
1.12.0.post0
1.12.1
1.13.0
1.13.1
1.14.0
1.14.0.post0
1.15.0
1.2
1.3
1.3.post0
1.3.post1
1.4
1.4.1
1.4.1.post0
1.4.1.post1
1.5.0
1.5.0.post0
1.6.0
1.7.0
1.7.1
1.7.2
1.7.3
1.8.0
1.8.1
1.8.2
1.8.2.post0
1.8.2.post1
1.9.0
1.9.1
1.9.1.post0
1.9.2
1.9.2.post0
Fixed in
1.16.0
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-25296
PYSEC-2026-1504
GHSA-wpq5-3366-mqw4
Jul 07, 2026
Label Studio allows Cross-Site Scripting (XSS) via GET request to `/projects/upload-example` endpoint
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
DescriptionLabel Studio's The vulnerability exists because the upload-example endpoint renders user-provided HTML content without proper sanitization on a GET request. This allows attackers to inject and execute arbitrary JavaScript in victims' browsers by getting them to visit a maliciously crafted URL. This is considered vulnerable because it enables attackers to execute JavaScript in victims' contexts, potentially allowing theft of sensitive data, session hijacking, or other malicious actions. Steps to reproduce
When executed, the payload causes the application to render an HTML page containing an img tag that fails to load, triggering the onerror event handler which executes base64-decoded JavaScript, demonstrating successful XSS execution in the victim's browser. Mitigations
ImpactThe vulnerability requires no special privileges and can be exploited by getting a victim to visit a crafted URL. The impact is high as it allows arbitrary JavaScript execution in victims' browsers, potentially exposing sensitive data or enabling account takeover through session theft. Affected versions
0.4.1
0.4.2
0.4.3
0.4.4
0.4.4.post1
0.4.4.post2
0.4.5
0.4.6
0.4.6.post1
0.4.6.post2
0.4.7
0.4.8
+ 76 more Show less
0.5.0
0.5.1
0.6.0
0.6.1
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.4.post0
0.7.4.post1
0.7.5.post1
0.7.5.post2
0.8.0
0.8.0.post0
0.8.1
0.8.1.post0
0.8.2
0.8.2.post0
0.9.0
0.9.0.post2
0.9.0.post3
0.9.0.post4
0.9.0.post5
0.9.1
0.9.1.post0
0.9.1.post1
0.9.1.post2
1.0.0
1.0.0.post0
1.0.0.post1
1.0.0.post2
1.0.0.post3
1.0.1
1.0.2
1.0.2.post0
1.1.0
1.1.0rc0
1.1.1
1.10.0
1.10.0.post0
1.10.1
1.11.0
1.12.0
1.12.0.post0
1.12.1
1.13.0
1.13.1
1.14.0
1.14.0.post0
1.15.0
1.2
1.3
1.3.post0
1.3.post1
1.4
1.4.1
1.4.1.post0
1.4.1.post1
1.5.0
1.5.0.post0
1.6.0
1.7.0
1.7.1
1.7.2
1.7.3
1.8.0
1.8.1
1.8.2
1.8.2.post0
1.8.2.post1
1.9.0
1.9.1
1.9.1.post0
1.9.2
1.9.2.post0
Fixed in
1.16.0
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-47783
GHSA-8jhr-wpcm-hh4h
PYSEC-2025-124
May 15, 2025
label-studio vulnerable to Cross-Site Scripting (Reflected) via the label_config parameter.
High
Network
Low
None
SummaryThe vulnerability allows an attacker to inject a malicious script into the context of a web page, which can lead to data theft, unauthorized actions on behalf of the user, and other attacks. DetailsThe vulnerability is reproducible when sending a properly formatted request to the
The vulnerability is specifically located in line 57, where HttpResponse is used.
PoCSend the following request after changing the
Or you can create a vulnerable HTML page by changing
Impact
Affected versions
0.4.1
0.4.2
0.4.3
0.4.4
0.4.4.post1
0.4.4.post2
0.4.5
0.4.6
0.4.6.post1
0.4.6.post2
0.4.7
0.4.8
+ 78 more Show less
0.5.0
0.5.1
0.6.0
0.6.1
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.4.post0
0.7.4.post1
0.7.5.post1
0.7.5.post2
0.8.0
0.8.0.post0
0.8.1
0.8.1.post0
0.8.2
0.8.2.post0
0.9.0
0.9.0.post2
0.9.0.post3
0.9.0.post4
0.9.0.post5
0.9.1
0.9.1.post0
0.9.1.post1
0.9.1.post2
1.0.0
1.0.0.post0
1.0.0.post1
1.0.0.post2
1.0.0.post3
1.0.1
1.0.2
1.0.2.post0
1.1.0
1.1.0rc0
1.1.1
1.10.0
1.10.0.post0
1.10.1
1.11.0
1.12.0
1.12.0.post0
1.12.1
1.13.0
1.13.1
1.14.0
1.14.0.post0
1.15.0
1.16.0
1.17.0
1.2
1.3
1.3.post0
1.3.post1
1.4
1.4.1
1.4.1.post0
1.4.1.post1
1.5.0
1.5.0.post0
1.6.0
1.7.0
1.7.1
1.7.2
1.7.3
1.8.0
1.8.1
1.8.2
1.8.2.post0
1.8.2.post1
1.9.0
1.9.1
1.9.1.post0
1.9.2
1.9.2.post0
Fixed in
1.18.0
References
Updated Jun 06, 2026 · Source: OSV.dev
CVE-2024-26152
PYSEC-2024-249
GHSA-6xv9-957j-qfhg
Feb 22, 2024
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
SummaryOn all Label Studio versions prior to 1.11.0, data imported via file upload feature is not properly sanitized prior to being rendered within a DetailsNeed permission to use the "data import" function. This was reproduced on Label Studio 1.10.1. PoC
The following are the contents of the files used in the PoC
ImpactMalicious scripts can be injected into the code, and when linked with vulnerabilities such as CSRF, it can cause even greater damage. In particular, It can become a source of further attacks, especially when linked to social engineering. Affected versions
0.4.1
0.4.2
0.4.3
0.4.4
0.4.4.post1
0.4.4.post2
0.4.5
0.4.6
0.4.6.post1
0.4.6.post2
0.4.7
0.4.8
+ 113 more Show less
0.5.0
0.5.1
0.6.0
0.6.1
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.4.post0
0.7.4.post1
0.7.5.post1
0.7.5.post2
0.8.0
0.8.0.post0
0.8.1
0.8.1.post0
0.8.2
0.8.2.post0
0.9.0
0.9.0.post2
0.9.0.post3
0.9.0.post4
0.9.0.post5
0.9.1
0.9.1.post0
0.9.1.post1
0.9.1.post2
1.0.0
1.0.0.post0
1.0.0.post1
1.0.0.post2
1.0.0.post3
1.0.1
1.0.2
1.0.2.post0
1.1.0
1.1.0rc0
1.1.1
1.10.0
1.10.0.post0
1.10.1
1.2
1.3
1.3.post0
1.3.post1
1.4
1.4.1
1.4.1.post0
1.4.1.post1
1.5.0
1.5.0.post0
1.6.0
1.7.0
1.7.1
1.7.2
1.7.3
1.8.0
1.8.1
1.8.2
1.8.2.post0
1.8.2.post1
1.9.0
1.9.1
1.9.1.post0
1.9.2
1.9.2.post0
v1.4.1
v1.4.0
v1.3.0
v1.2.0
v1.1.1
v1.1.0
v1.0.2
v1.0.1
v1.0.0
v0.9.1.post1
v0.9.1.post0
v0.9.0.post5
v0.9.0.post4
v0.9.0.post3
v0.9.0
v0.8.2
v0.8.1
v0.8.0
v0.7.5.post0
v0.7.3
v0.7.2
v0.7.1
v0.7.0
v0.6.1
v0.6.0
v0.5.1
v0.4.8
v0.4.7
v0.4.6
v0.4.5
v0.4.4
v0.4.0
v0.3.0
v0.2.2
v.0.2.1-8
v.0.2.1-5
v.0.2.1-4
v.0.2.1-3
v.0.2.1-2
v.0.2.0
v.0.1.6
v.0.1.5
v.0.1.4
v.0.1.2
v.0.1.1
v.0.1.0
Fixed in
1.11.0
References
Updated Jun 10, 2026 · Source: OSV.dev
CVE-2023-47116
GHSA-p59w-9gqw-wj8r
PYSEC-2024-127
Jan 31, 2024
Label Studio SSRF on Import Bypassing `SSRF_PROTECTION_ENABLED` Protections
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
IntroductionThis write-up describes a vulnerability found in Label Studio, a popular open source data labeling tool. The vulnerability affects all versions of Label Studio prior to OverviewLabel Studio's SSRF protections that can be enabled by setting the DescriptionThe following
The
The issue here is the SSRF validation is only performed before the request is sent, and does not validate the destination IP address. Therefore, an attacker can either redirect the request or perform a DNS rebinding attack to bypass this protection. Proof of ConceptBoth the HTTP redirection and DNS rebinding methods for bypassing Label Studio's SSRF protections are explained below. HTTP RedirectionThe python
DNS Rebinding AttackDNS rebinding can bypass SSRF protections by resolving to an external IP address for the first resolution, but when the request is sent resolves to an internal IP address that is blocked. For an example, the domain ImpactSSRF vulnerabilities pose a significant risk on cloud environments, since instance credentials are managed by internal web APIs. An attacker can bypass Label Studio's SSRF protections to access internal web servers and partially compromise the confidentiality of those internal servers. Remediation Advice
Discovered
Affected versions
0.4.1
0.4.2
0.4.3
0.4.4
0.4.4.post1
0.4.4.post2
0.4.5
0.4.6
0.4.6.post1
0.4.6.post2
0.4.7
0.4.8
+ 67 more Show less
0.5.0
0.5.1
0.6.0
0.6.1
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.4.post0
0.7.4.post1
0.7.5.post1
0.7.5.post2
0.8.0
0.8.0.post0
0.8.1
0.8.1.post0
0.8.2
0.8.2.post0
0.9.0
0.9.0.post2
0.9.0.post3
0.9.0.post4
0.9.0.post5
0.9.1
0.9.1.post0
0.9.1.post1
0.9.1.post2
1.0.0
1.0.0.post0
1.0.0.post1
1.0.0.post2
1.0.0.post3
1.0.1
1.0.2
1.0.2.post0
1.1.0
1.1.0rc0
1.1.1
1.10.0
1.10.0.post0
1.10.1
1.2
1.3
1.3.post0
1.3.post1
1.4
1.4.1
1.4.1.post0
1.4.1.post1
1.5.0
1.5.0.post0
1.6.0
1.7.0
1.7.1
1.7.2
1.7.3
1.8.0
1.8.1
1.8.2
1.8.2.post0
1.8.2.post1
1.9.0
1.9.1
1.9.1.post0
1.9.2
1.9.2.post0
Fixed in
1.11.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-23633
GHSA-fq23-g58m-799r
PYSEC-2024-128
Jan 24, 2024
Cross-site Scripting Vulnerability on Data Import
4.7
/ 10
Medium
Network
Low
None
Required
Changed
Low
None
None
IntroductionThis write-up describes a vulnerability found in Label Studio, a popular open source data labeling tool. The vulnerability affects all versions of Label Studio prior to OverviewLabel Studio had a remote import feature allowed users to import data from a remote web source, that was downloaded and could be viewed on the website. This feature could had been abused to download a HTML file that executed malicious JavaScript code in the context of the Label Studio website. DescriptionThe following code snippet in Label Studio showed that is a URL passed the SSRF verification checks, the contents of the file would be downloaded using the filename in the URL.
The downloaded file path could then be retrieved by sending a request to
Since the Proof of ConceptBelow were the steps to recreate this issue:
ImpactExecuting arbitrary JavaScript could result in an attacker performing malicious actions on Label Studio users if they visit the crafted avatar image. For an example, an attacker can craft a JavaScript payload that adds a new Django Super Administrator user if a Django administrator visits the image. Remediation Advice
Discovered
Affected versions
0.4.1
0.4.2
0.4.3
0.4.4
0.4.4.post1
0.4.4.post2
0.4.5
0.4.6
0.4.6.post1
0.4.6.post2
0.4.7
0.4.8
+ 66 more Show less
0.5.0
0.5.1
0.6.0
0.6.1
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.4.post0
0.7.4.post1
0.7.5.post1
0.7.5.post2
0.8.0
0.8.0.post0
0.8.1
0.8.1.post0
0.8.2
0.8.2.post0
0.9.0
0.9.0.post2
0.9.0.post3
0.9.0.post4
0.9.0.post5
0.9.1
0.9.1.post0
0.9.1.post1
0.9.1.post2
1.0.0
1.0.0.post0
1.0.0.post1
1.0.0.post2
1.0.0.post3
1.0.1
1.0.2
1.0.2.post0
1.1.0
1.1.0rc0
1.1.1
1.10.0
1.10.0.post0
1.2
1.3
1.3.post0
1.3.post1
1.4
1.4.1
1.4.1.post0
1.4.1.post1
1.5.0
1.5.0.post0
1.6.0
1.7.0
1.7.1
1.7.2
1.7.3
1.8.0
1.8.1
1.8.2
1.8.2.post0
1.8.2.post1
1.9.0
1.9.1
1.9.1.post0
1.9.2
1.9.2.post0
Fixed in
1.10.1
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2023-47115
GHSA-q68h-xwq5-mm7x
PYSEC-2024-126
Jan 24, 2024
Cross-site Scripting Vulnerability on Avatar Upload
7.1
/ 10
High
Network
Low
None
Required
Changed
Low
Low
Low
IntroductionThis write-up describes a vulnerability found in Label Studio, a popular open source data labeling tool. The vulnerability affects all versions of Label Studio prior to OverviewLabel Studio has a cross-site scripting (XSS) vulnerability that could be exploited when an authenticated user uploads a crafted image file for their avatar that gets rendered as a HTML file on the website. DescriptionThe following code snippet in Label Studio shows that the only verification check is that the file is an image by extracting the dimensions from the file.
Label Studio serves avatar images using Django's built-in
The issue with the Django Proof of ConceptBelow are the steps to reproduce this issue and execute JavaScript code in the context of the Label Studio website.
ImpactExecuting arbitrary JavaScript could result in an attacker performing malicious actions on Label Studio users if they visit the crafted avatar image. For an example, an attacker can craft a JavaScript payload that adds a new Django Super Administrator user if a Django administrator visits the image. Remediation Advice
Discovered
Affected versions
0.4.1
0.4.2
0.4.3
0.4.4
0.4.4.post1
0.4.4.post2
0.4.5
0.4.6
0.4.6.post1
0.4.6.post2
0.4.7
0.4.8
+ 62 more Show less
0.5.0
0.5.1
0.6.0
0.6.1
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.4.post0
0.7.4.post1
0.7.5.post1
0.7.5.post2
0.8.0
0.8.0.post0
0.8.1
0.8.1.post0
0.8.2
0.8.2.post0
0.9.0
0.9.0.post2
0.9.0.post3
0.9.0.post4
0.9.0.post5
0.9.1
0.9.1.post0
0.9.1.post1
0.9.1.post2
1.0.0
1.0.0.post0
1.0.0.post1
1.0.0.post2
1.0.0.post3
1.0.1
1.0.2
1.0.2.post0
1.1.0
1.1.0rc0
1.1.1
1.2
1.3
1.3.post0
1.3.post1
1.4
1.4.1
1.4.1.post0
1.4.1.post1
1.5.0
1.5.0.post0
1.6.0
1.7.0
1.7.1
1.7.2
1.7.3
1.8.0
1.8.1
1.8.2
1.8.2.post0
1.8.2.post1
1.9.0
1.9.1
1.9.1.post0
Fixed in
1.9.2
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2023-47117
GHSA-6hjj-gq77-j4qw
PYSEC-2023-275
Nov 14, 2023
Label Studio Object Relational Mapper Leak Vulnerability in Filtering Task
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
IntroductionThis write-up describes a vulnerability found in Label Studio, a popular open source data labeling tool. The vulnerability affects all versions of Label Studio prior to OverviewIn all current versions of Label Studio, the application allows users to insecurely set filters for filtering tasks. An attacker can construct a filter chain to filter tasks based on sensitive fields for all user accounts on the platform by exploiting Django's Object Relational Mapper (ORM). Since the results of query can be manipulated by the ORM filter, an attacker can leak these sensitive fields character by character. For an example, the following filter chain will task results by the password hash of an account on Label Studio.
For consistency, this type of vulnerability will be termed as ORM Leak in the rest of this disclosure. In addition, Label Studio had a hard coded secret key that an attacker can use to forge a session token of any user by exploiting this ORM Leak vulnerability to leak account password hashes. DescriptionThe following code snippet from the
These
The
The following code snippet of the
Finally, the
Proof of ConceptBelow are the steps to exploit about how to exploit this vulnerability to leak the password hash of an account on Label Studio.
The following example GIF demonstrates exploiting this ORM Leak vulnerability to retrieve the password hash
ImpactThis vulnerability can be exploited to completely compromise the confidentiality of highly sensitive account information, such as account password hashes. For all versions Remediation Advice
Discovered
| ||
1.8.2.post1
pre
10 CVEs
CVE-2026-22033
PYSEC-2026-1502
GHSA-2mq9-hm29-8qch
Jul 07, 2026
Label Studio is vulnerable to full account takeover by chaining Stored XSS + IDOR in User Profile via custom_hotkeys field
Critical
Network
Low
Low
None
PrologueThese vulnerabilities have been found and chained by DCODX-AI. Validation of the exploit chain has been confirmed manually. SummaryA persistent stored cross-site scripting (XSS) vulnerability exists in the custom_hotkeys functionality of the application. An authenticated attacker (or one who can trick a user/administrator into updating their custom_hotkeys) can inject JavaScript code that executes in other users’ browsers when those users load any page using the DetailsWithin
Here, user.custom_hotkeys is run through json_dumps_ensure_ascii (in In
The serializer allows
When another user loads a page using templates/base.html (for example PoC
Example request
Example response
ImpactExploitation impact:
Who is impacted:
Affected versions
0.4.1
0.4.2
0.4.3
0.4.4
0.4.4.post1
0.4.4.post2
0.4.5
0.4.6
0.4.6.post1
0.4.6.post2
0.4.7
0.4.8
+ 83 more Show less
0.5.0
0.5.1
0.6.0
0.6.1
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.4.post0
0.7.4.post1
0.7.5.post1
0.7.5.post2
0.8.0
0.8.0.post0
0.8.1
0.8.1.post0
0.8.2
0.8.2.post0
0.9.0
0.9.0.post2
0.9.0.post3
0.9.0.post4
0.9.0.post5
0.9.1
0.9.1.post0
0.9.1.post1
0.9.1.post2
1.0.0
1.0.0.post0
1.0.0.post1
1.0.0.post2
1.0.0.post3
1.0.1
1.0.2
1.0.2.post0
1.1.0
1.1.0rc0
1.1.1
1.10.0
1.10.0.post0
1.10.1
1.11.0
1.12.0
1.12.0.post0
1.12.1
1.13.0
1.13.1
1.14.0
1.14.0.post0
1.15.0
1.16.0
1.17.0
1.18.0
1.19.0
1.2
1.20.0
1.21.0
1.22.0
1.3
1.3.post0
1.3.post1
1.4
1.4.1
1.4.1.post0
1.4.1.post1
1.5.0
1.5.0.post0
1.6.0
1.7.0
1.7.1
1.7.2
1.7.3
1.8.0
1.8.1
1.8.2
1.8.2.post0
1.8.2.post1
1.9.0
1.9.1
1.9.1.post0
1.9.2
1.9.2.post0
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-25297
PYSEC-2026-1503
GHSA-m238-fmcw-wh58
Jul 07, 2026
Label Studio allows Server-Side Request Forgery in the S3 Storage Endpoint
8.6
/ 10
High
Network
Low
None
None
Changed
High
None
None
DescriptionLabel Studio's S3 storage integration feature contains a Server-Side Request Forgery (SSRF) vulnerability in its endpoint configuration. When creating an S3 storage connection, the application allows users to specify a custom S3 endpoint URL via the s3_endpoint parameter. This endpoint URL is passed directly to the boto3 AWS SDK without proper validation or restrictions on the protocol or destination. The vulnerability allows an attacker to make the application send HTTP requests to arbitrary internal services by specifying them as the S3 endpoint. When the storage sync operation is triggered, the application attempts to make S3 API calls to the specified endpoint, effectively making HTTP requests to the target service and returning the response in error messages. This SSRF vulnerability enables attackers to bypass network segmentation and access internal services that should not be accessible from the external network. The vulnerability is particularly severe because error messages from failed requests contain the full response body, allowing data exfiltration from internal services. Steps to reproduce
The application will attempt to connect to the specified endpoint URL as if it were an S3 service. When the request fails due to invalid S3 API responses, the error message will contain the raw response from the internal service, allowing access to internal resources. Mitigations
ImpactThis vulnerability has high severity as it allows authenticated users to make requests to arbitrary internal services from the application server, potentially exposing sensitive internal resources and bypassing network segmentation. The inclusion of response data in error messages makes this particularly effective for data exfiltration. Affected versions
0.4.1
0.4.2
0.4.3
0.4.4
0.4.4.post1
0.4.4.post2
0.4.5
0.4.6
0.4.6.post1
0.4.6.post2
0.4.7
0.4.8
+ 76 more Show less
0.5.0
0.5.1
0.6.0
0.6.1
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.4.post0
0.7.4.post1
0.7.5.post1
0.7.5.post2
0.8.0
0.8.0.post0
0.8.1
0.8.1.post0
0.8.2
0.8.2.post0
0.9.0
0.9.0.post2
0.9.0.post3
0.9.0.post4
0.9.0.post5
0.9.1
0.9.1.post0
0.9.1.post1
0.9.1.post2
1.0.0
1.0.0.post0
1.0.0.post1
1.0.0.post2
1.0.0.post3
1.0.1
1.0.2
1.0.2.post0
1.1.0
1.1.0rc0
1.1.1
1.10.0
1.10.0.post0
1.10.1
1.11.0
1.12.0
1.12.0.post0
1.12.1
1.13.0
1.13.1
1.14.0
1.14.0.post0
1.15.0
1.2
1.3
1.3.post0
1.3.post1
1.4
1.4.1
1.4.1.post0
1.4.1.post1
1.5.0
1.5.0.post0
1.6.0
1.7.0
1.7.1
1.7.2
1.7.3
1.8.0
1.8.1
1.8.2
1.8.2.post0
1.8.2.post1
1.9.0
1.9.1
1.9.1.post0
1.9.2
1.9.2.post0
Fixed in
1.16.0
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-25296
PYSEC-2026-1504
GHSA-wpq5-3366-mqw4
Jul 07, 2026
Label Studio allows Cross-Site Scripting (XSS) via GET request to `/projects/upload-example` endpoint
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
DescriptionLabel Studio's The vulnerability exists because the upload-example endpoint renders user-provided HTML content without proper sanitization on a GET request. This allows attackers to inject and execute arbitrary JavaScript in victims' browsers by getting them to visit a maliciously crafted URL. This is considered vulnerable because it enables attackers to execute JavaScript in victims' contexts, potentially allowing theft of sensitive data, session hijacking, or other malicious actions. Steps to reproduce
When executed, the payload causes the application to render an HTML page containing an img tag that fails to load, triggering the onerror event handler which executes base64-decoded JavaScript, demonstrating successful XSS execution in the victim's browser. Mitigations
ImpactThe vulnerability requires no special privileges and can be exploited by getting a victim to visit a crafted URL. The impact is high as it allows arbitrary JavaScript execution in victims' browsers, potentially exposing sensitive data or enabling account takeover through session theft. Affected versions
0.4.1
0.4.2
0.4.3
0.4.4
0.4.4.post1
0.4.4.post2
0.4.5
0.4.6
0.4.6.post1
0.4.6.post2
0.4.7
0.4.8
+ 76 more Show less
0.5.0
0.5.1
0.6.0
0.6.1
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.4.post0
0.7.4.post1
0.7.5.post1
0.7.5.post2
0.8.0
0.8.0.post0
0.8.1
0.8.1.post0
0.8.2
0.8.2.post0
0.9.0
0.9.0.post2
0.9.0.post3
0.9.0.post4
0.9.0.post5
0.9.1
0.9.1.post0
0.9.1.post1
0.9.1.post2
1.0.0
1.0.0.post0
1.0.0.post1
1.0.0.post2
1.0.0.post3
1.0.1
1.0.2
1.0.2.post0
1.1.0
1.1.0rc0
1.1.1
1.10.0
1.10.0.post0
1.10.1
1.11.0
1.12.0
1.12.0.post0
1.12.1
1.13.0
1.13.1
1.14.0
1.14.0.post0
1.15.0
1.2
1.3
1.3.post0
1.3.post1
1.4
1.4.1
1.4.1.post0
1.4.1.post1
1.5.0
1.5.0.post0
1.6.0
1.7.0
1.7.1
1.7.2
1.7.3
1.8.0
1.8.1
1.8.2
1.8.2.post0
1.8.2.post1
1.9.0
1.9.1
1.9.1.post0
1.9.2
1.9.2.post0
Fixed in
1.16.0
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-47783
GHSA-8jhr-wpcm-hh4h
PYSEC-2025-124
May 15, 2025
label-studio vulnerable to Cross-Site Scripting (Reflected) via the label_config parameter.
High
Network
Low
None
SummaryThe vulnerability allows an attacker to inject a malicious script into the context of a web page, which can lead to data theft, unauthorized actions on behalf of the user, and other attacks. DetailsThe vulnerability is reproducible when sending a properly formatted request to the
The vulnerability is specifically located in line 57, where HttpResponse is used.
PoCSend the following request after changing the
Or you can create a vulnerable HTML page by changing
Impact
Affected versions
0.4.1
0.4.2
0.4.3
0.4.4
0.4.4.post1
0.4.4.post2
0.4.5
0.4.6
0.4.6.post1
0.4.6.post2
0.4.7
0.4.8
+ 78 more Show less
0.5.0
0.5.1
0.6.0
0.6.1
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.4.post0
0.7.4.post1
0.7.5.post1
0.7.5.post2
0.8.0
0.8.0.post0
0.8.1
0.8.1.post0
0.8.2
0.8.2.post0
0.9.0
0.9.0.post2
0.9.0.post3
0.9.0.post4
0.9.0.post5
0.9.1
0.9.1.post0
0.9.1.post1
0.9.1.post2
1.0.0
1.0.0.post0
1.0.0.post1
1.0.0.post2
1.0.0.post3
1.0.1
1.0.2
1.0.2.post0
1.1.0
1.1.0rc0
1.1.1
1.10.0
1.10.0.post0
1.10.1
1.11.0
1.12.0
1.12.0.post0
1.12.1
1.13.0
1.13.1
1.14.0
1.14.0.post0
1.15.0
1.16.0
1.17.0
1.2
1.3
1.3.post0
1.3.post1
1.4
1.4.1
1.4.1.post0
1.4.1.post1
1.5.0
1.5.0.post0
1.6.0
1.7.0
1.7.1
1.7.2
1.7.3
1.8.0
1.8.1
1.8.2
1.8.2.post0
1.8.2.post1
1.9.0
1.9.1
1.9.1.post0
1.9.2
1.9.2.post0
Fixed in
1.18.0
References
Updated Jun 06, 2026 · Source: OSV.dev
CVE-2024-26152
PYSEC-2024-249
GHSA-6xv9-957j-qfhg
Feb 22, 2024
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
SummaryOn all Label Studio versions prior to 1.11.0, data imported via file upload feature is not properly sanitized prior to being rendered within a DetailsNeed permission to use the "data import" function. This was reproduced on Label Studio 1.10.1. PoC
The following are the contents of the files used in the PoC
ImpactMalicious scripts can be injected into the code, and when linked with vulnerabilities such as CSRF, it can cause even greater damage. In particular, It can become a source of further attacks, especially when linked to social engineering. Affected versions
0.4.1
0.4.2
0.4.3
0.4.4
0.4.4.post1
0.4.4.post2
0.4.5
0.4.6
0.4.6.post1
0.4.6.post2
0.4.7
0.4.8
+ 113 more Show less
0.5.0
0.5.1
0.6.0
0.6.1
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.4.post0
0.7.4.post1
0.7.5.post1
0.7.5.post2
0.8.0
0.8.0.post0
0.8.1
0.8.1.post0
0.8.2
0.8.2.post0
0.9.0
0.9.0.post2
0.9.0.post3
0.9.0.post4
0.9.0.post5
0.9.1
0.9.1.post0
0.9.1.post1
0.9.1.post2
1.0.0
1.0.0.post0
1.0.0.post1
1.0.0.post2
1.0.0.post3
1.0.1
1.0.2
1.0.2.post0
1.1.0
1.1.0rc0
1.1.1
1.10.0
1.10.0.post0
1.10.1
1.2
1.3
1.3.post0
1.3.post1
1.4
1.4.1
1.4.1.post0
1.4.1.post1
1.5.0
1.5.0.post0
1.6.0
1.7.0
1.7.1
1.7.2
1.7.3
1.8.0
1.8.1
1.8.2
1.8.2.post0
1.8.2.post1
1.9.0
1.9.1
1.9.1.post0
1.9.2
1.9.2.post0
v1.4.1
v1.4.0
v1.3.0
v1.2.0
v1.1.1
v1.1.0
v1.0.2
v1.0.1
v1.0.0
v0.9.1.post1
v0.9.1.post0
v0.9.0.post5
v0.9.0.post4
v0.9.0.post3
v0.9.0
v0.8.2
v0.8.1
v0.8.0
v0.7.5.post0
v0.7.3
v0.7.2
v0.7.1
v0.7.0
v0.6.1
v0.6.0
v0.5.1
v0.4.8
v0.4.7
v0.4.6
v0.4.5
v0.4.4
v0.4.0
v0.3.0
v0.2.2
v.0.2.1-8
v.0.2.1-5
v.0.2.1-4
v.0.2.1-3
v.0.2.1-2
v.0.2.0
v.0.1.6
v.0.1.5
v.0.1.4
v.0.1.2
v.0.1.1
v.0.1.0
Fixed in
1.11.0
References
Updated Jun 10, 2026 · Source: OSV.dev
CVE-2023-47116
GHSA-p59w-9gqw-wj8r
PYSEC-2024-127
Jan 31, 2024
Label Studio SSRF on Import Bypassing `SSRF_PROTECTION_ENABLED` Protections
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
IntroductionThis write-up describes a vulnerability found in Label Studio, a popular open source data labeling tool. The vulnerability affects all versions of Label Studio prior to OverviewLabel Studio's SSRF protections that can be enabled by setting the DescriptionThe following
The
The issue here is the SSRF validation is only performed before the request is sent, and does not validate the destination IP address. Therefore, an attacker can either redirect the request or perform a DNS rebinding attack to bypass this protection. Proof of ConceptBoth the HTTP redirection and DNS rebinding methods for bypassing Label Studio's SSRF protections are explained below. HTTP RedirectionThe python
DNS Rebinding AttackDNS rebinding can bypass SSRF protections by resolving to an external IP address for the first resolution, but when the request is sent resolves to an internal IP address that is blocked. For an example, the domain ImpactSSRF vulnerabilities pose a significant risk on cloud environments, since instance credentials are managed by internal web APIs. An attacker can bypass Label Studio's SSRF protections to access internal web servers and partially compromise the confidentiality of those internal servers. Remediation Advice
Discovered
Affected versions
0.4.1
0.4.2
0.4.3
0.4.4
0.4.4.post1
0.4.4.post2
0.4.5
0.4.6
0.4.6.post1
0.4.6.post2
0.4.7
0.4.8
+ 67 more Show less
0.5.0
0.5.1
0.6.0
0.6.1
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.4.post0
0.7.4.post1
0.7.5.post1
0.7.5.post2
0.8.0
0.8.0.post0
0.8.1
0.8.1.post0
0.8.2
0.8.2.post0
0.9.0
0.9.0.post2
0.9.0.post3
0.9.0.post4
0.9.0.post5
0.9.1
0.9.1.post0
0.9.1.post1
0.9.1.post2
1.0.0
1.0.0.post0
1.0.0.post1
1.0.0.post2
1.0.0.post3
1.0.1
1.0.2
1.0.2.post0
1.1.0
1.1.0rc0
1.1.1
1.10.0
1.10.0.post0
1.10.1
1.2
1.3
1.3.post0
1.3.post1
1.4
1.4.1
1.4.1.post0
1.4.1.post1
1.5.0
1.5.0.post0
1.6.0
1.7.0
1.7.1
1.7.2
1.7.3
1.8.0
1.8.1
1.8.2
1.8.2.post0
1.8.2.post1
1.9.0
1.9.1
1.9.1.post0
1.9.2
1.9.2.post0
Fixed in
1.11.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-23633
GHSA-fq23-g58m-799r
PYSEC-2024-128
Jan 24, 2024
Cross-site Scripting Vulnerability on Data Import
4.7
/ 10
Medium
Network
Low
None
Required
Changed
Low
None
None
IntroductionThis write-up describes a vulnerability found in Label Studio, a popular open source data labeling tool. The vulnerability affects all versions of Label Studio prior to OverviewLabel Studio had a remote import feature allowed users to import data from a remote web source, that was downloaded and could be viewed on the website. This feature could had been abused to download a HTML file that executed malicious JavaScript code in the context of the Label Studio website. DescriptionThe following code snippet in Label Studio showed that is a URL passed the SSRF verification checks, the contents of the file would be downloaded using the filename in the URL.
The downloaded file path could then be retrieved by sending a request to
Since the Proof of ConceptBelow were the steps to recreate this issue:
ImpactExecuting arbitrary JavaScript could result in an attacker performing malicious actions on Label Studio users if they visit the crafted avatar image. For an example, an attacker can craft a JavaScript payload that adds a new Django Super Administrator user if a Django administrator visits the image. Remediation Advice
Discovered
Affected versions
0.4.1
0.4.2
0.4.3
0.4.4
0.4.4.post1
0.4.4.post2
0.4.5
0.4.6
0.4.6.post1
0.4.6.post2
0.4.7
0.4.8
+ 66 more Show less
0.5.0
0.5.1
0.6.0
0.6.1
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.4.post0
0.7.4.post1
0.7.5.post1
0.7.5.post2
0.8.0
0.8.0.post0
0.8.1
0.8.1.post0
0.8.2
0.8.2.post0
0.9.0
0.9.0.post2
0.9.0.post3
0.9.0.post4
0.9.0.post5
0.9.1
0.9.1.post0
0.9.1.post1
0.9.1.post2
1.0.0
1.0.0.post0
1.0.0.post1
1.0.0.post2
1.0.0.post3
1.0.1
1.0.2
1.0.2.post0
1.1.0
1.1.0rc0
1.1.1
1.10.0
1.10.0.post0
1.2
1.3
1.3.post0
1.3.post1
1.4
1.4.1
1.4.1.post0
1.4.1.post1
1.5.0
1.5.0.post0
1.6.0
1.7.0
1.7.1
1.7.2
1.7.3
1.8.0
1.8.1
1.8.2
1.8.2.post0
1.8.2.post1
1.9.0
1.9.1
1.9.1.post0
1.9.2
1.9.2.post0
Fixed in
1.10.1
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2023-47115
GHSA-q68h-xwq5-mm7x
PYSEC-2024-126
Jan 24, 2024
Cross-site Scripting Vulnerability on Avatar Upload
7.1
/ 10
High
Network
Low
None
Required
Changed
Low
Low
Low
IntroductionThis write-up describes a vulnerability found in Label Studio, a popular open source data labeling tool. The vulnerability affects all versions of Label Studio prior to OverviewLabel Studio has a cross-site scripting (XSS) vulnerability that could be exploited when an authenticated user uploads a crafted image file for their avatar that gets rendered as a HTML file on the website. DescriptionThe following code snippet in Label Studio shows that the only verification check is that the file is an image by extracting the dimensions from the file.
Label Studio serves avatar images using Django's built-in
The issue with the Django Proof of ConceptBelow are the steps to reproduce this issue and execute JavaScript code in the context of the Label Studio website.
ImpactExecuting arbitrary JavaScript could result in an attacker performing malicious actions on Label Studio users if they visit the crafted avatar image. For an example, an attacker can craft a JavaScript payload that adds a new Django Super Administrator user if a Django administrator visits the image. Remediation Advice
Discovered
Affected versions
0.4.1
0.4.2
0.4.3
0.4.4
0.4.4.post1
0.4.4.post2
0.4.5
0.4.6
0.4.6.post1
0.4.6.post2
0.4.7
0.4.8
+ 62 more Show less
0.5.0
0.5.1
0.6.0
0.6.1
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.4.post0
0.7.4.post1
0.7.5.post1
0.7.5.post2
0.8.0
0.8.0.post0
0.8.1
0.8.1.post0
0.8.2
0.8.2.post0
0.9.0
0.9.0.post2
0.9.0.post3
0.9.0.post4
0.9.0.post5
0.9.1
0.9.1.post0
0.9.1.post1
0.9.1.post2
1.0.0
1.0.0.post0
1.0.0.post1
1.0.0.post2
1.0.0.post3
1.0.1
1.0.2
1.0.2.post0
1.1.0
1.1.0rc0
1.1.1
1.2
1.3
1.3.post0
1.3.post1
1.4
1.4.1
1.4.1.post0
1.4.1.post1
1.5.0
1.5.0.post0
1.6.0
1.7.0
1.7.1
1.7.2
1.7.3
1.8.0
1.8.1
1.8.2
1.8.2.post0
1.8.2.post1
1.9.0
1.9.1
1.9.1.post0
Fixed in
1.9.2
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2023-47117
GHSA-6hjj-gq77-j4qw
PYSEC-2023-275
Nov 14, 2023
Label Studio Object Relational Mapper Leak Vulnerability in Filtering Task
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
IntroductionThis write-up describes a vulnerability found in Label Studio, a popular open source data labeling tool. The vulnerability affects all versions of Label Studio prior to OverviewIn all current versions of Label Studio, the application allows users to insecurely set filters for filtering tasks. An attacker can construct a filter chain to filter tasks based on sensitive fields for all user accounts on the platform by exploiting Django's Object Relational Mapper (ORM). Since the results of query can be manipulated by the ORM filter, an attacker can leak these sensitive fields character by character. For an example, the following filter chain will task results by the password hash of an account on Label Studio.
For consistency, this type of vulnerability will be termed as ORM Leak in the rest of this disclosure. In addition, Label Studio had a hard coded secret key that an attacker can use to forge a session token of any user by exploiting this ORM Leak vulnerability to leak account password hashes. DescriptionThe following code snippet from the
These
The
The following code snippet of the
Finally, the
Proof of ConceptBelow are the steps to exploit about how to exploit this vulnerability to leak the password hash of an account on Label Studio.
The following example GIF demonstrates exploiting this ORM Leak vulnerability to retrieve the password hash
ImpactThis vulnerability can be exploited to completely compromise the confidentiality of highly sensitive account information, such as account password hashes. For all versions Remediation Advice
Discovered
| ||
1.8.2.post0
pre
10 CVEs
CVE-2026-22033
PYSEC-2026-1502
GHSA-2mq9-hm29-8qch
Jul 07, 2026
Label Studio is vulnerable to full account takeover by chaining Stored XSS + IDOR in User Profile via custom_hotkeys field
Critical
Network
Low
Low
None
PrologueThese vulnerabilities have been found and chained by DCODX-AI. Validation of the exploit chain has been confirmed manually. SummaryA persistent stored cross-site scripting (XSS) vulnerability exists in the custom_hotkeys functionality of the application. An authenticated attacker (or one who can trick a user/administrator into updating their custom_hotkeys) can inject JavaScript code that executes in other users’ browsers when those users load any page using the DetailsWithin
Here, user.custom_hotkeys is run through json_dumps_ensure_ascii (in In
The serializer allows
When another user loads a page using templates/base.html (for example PoC
Example request
Example response
ImpactExploitation impact:
Who is impacted:
Affected versions
0.4.1
0.4.2
0.4.3
0.4.4
0.4.4.post1
0.4.4.post2
0.4.5
0.4.6
0.4.6.post1
0.4.6.post2
0.4.7
0.4.8
+ 83 more Show less
0.5.0
0.5.1
0.6.0
0.6.1
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.4.post0
0.7.4.post1
0.7.5.post1
0.7.5.post2
0.8.0
0.8.0.post0
0.8.1
0.8.1.post0
0.8.2
0.8.2.post0
0.9.0
0.9.0.post2
0.9.0.post3
0.9.0.post4
0.9.0.post5
0.9.1
0.9.1.post0
0.9.1.post1
0.9.1.post2
1.0.0
1.0.0.post0
1.0.0.post1
1.0.0.post2
1.0.0.post3
1.0.1
1.0.2
1.0.2.post0
1.1.0
1.1.0rc0
1.1.1
1.10.0
1.10.0.post0
1.10.1
1.11.0
1.12.0
1.12.0.post0
1.12.1
1.13.0
1.13.1
1.14.0
1.14.0.post0
1.15.0
1.16.0
1.17.0
1.18.0
1.19.0
1.2
1.20.0
1.21.0
1.22.0
1.3
1.3.post0
1.3.post1
1.4
1.4.1
1.4.1.post0
1.4.1.post1
1.5.0
1.5.0.post0
1.6.0
1.7.0
1.7.1
1.7.2
1.7.3
1.8.0
1.8.1
1.8.2
1.8.2.post0
1.8.2.post1
1.9.0
1.9.1
1.9.1.post0
1.9.2
1.9.2.post0
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-25297
PYSEC-2026-1503
GHSA-m238-fmcw-wh58
Jul 07, 2026
Label Studio allows Server-Side Request Forgery in the S3 Storage Endpoint
8.6
/ 10
High
Network
Low
None
None
Changed
High
None
None
DescriptionLabel Studio's S3 storage integration feature contains a Server-Side Request Forgery (SSRF) vulnerability in its endpoint configuration. When creating an S3 storage connection, the application allows users to specify a custom S3 endpoint URL via the s3_endpoint parameter. This endpoint URL is passed directly to the boto3 AWS SDK without proper validation or restrictions on the protocol or destination. The vulnerability allows an attacker to make the application send HTTP requests to arbitrary internal services by specifying them as the S3 endpoint. When the storage sync operation is triggered, the application attempts to make S3 API calls to the specified endpoint, effectively making HTTP requests to the target service and returning the response in error messages. This SSRF vulnerability enables attackers to bypass network segmentation and access internal services that should not be accessible from the external network. The vulnerability is particularly severe because error messages from failed requests contain the full response body, allowing data exfiltration from internal services. Steps to reproduce
The application will attempt to connect to the specified endpoint URL as if it were an S3 service. When the request fails due to invalid S3 API responses, the error message will contain the raw response from the internal service, allowing access to internal resources. Mitigations
ImpactThis vulnerability has high severity as it allows authenticated users to make requests to arbitrary internal services from the application server, potentially exposing sensitive internal resources and bypassing network segmentation. The inclusion of response data in error messages makes this particularly effective for data exfiltration. Affected versions
0.4.1
0.4.2
0.4.3
0.4.4
0.4.4.post1
0.4.4.post2
0.4.5
0.4.6
0.4.6.post1
0.4.6.post2
0.4.7
0.4.8
+ 76 more Show less
0.5.0
0.5.1
0.6.0
0.6.1
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.4.post0
0.7.4.post1
0.7.5.post1
0.7.5.post2
0.8.0
0.8.0.post0
0.8.1
0.8.1.post0
0.8.2
0.8.2.post0
0.9.0
0.9.0.post2
0.9.0.post3
0.9.0.post4
0.9.0.post5
0.9.1
0.9.1.post0
0.9.1.post1
0.9.1.post2
1.0.0
1.0.0.post0
1.0.0.post1
1.0.0.post2
1.0.0.post3
1.0.1
1.0.2
1.0.2.post0
1.1.0
1.1.0rc0
1.1.1
1.10.0
1.10.0.post0
1.10.1
1.11.0
1.12.0
1.12.0.post0
1.12.1
1.13.0
1.13.1
1.14.0
1.14.0.post0
1.15.0
1.2
1.3
1.3.post0
1.3.post1
1.4
1.4.1
1.4.1.post0
1.4.1.post1
1.5.0
1.5.0.post0
1.6.0
1.7.0
1.7.1
1.7.2
1.7.3
1.8.0
1.8.1
1.8.2
1.8.2.post0
1.8.2.post1
1.9.0
1.9.1
1.9.1.post0
1.9.2
1.9.2.post0
Fixed in
1.16.0
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-25296
PYSEC-2026-1504
GHSA-wpq5-3366-mqw4
Jul 07, 2026
Label Studio allows Cross-Site Scripting (XSS) via GET request to `/projects/upload-example` endpoint
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
DescriptionLabel Studio's The vulnerability exists because the upload-example endpoint renders user-provided HTML content without proper sanitization on a GET request. This allows attackers to inject and execute arbitrary JavaScript in victims' browsers by getting them to visit a maliciously crafted URL. This is considered vulnerable because it enables attackers to execute JavaScript in victims' contexts, potentially allowing theft of sensitive data, session hijacking, or other malicious actions. Steps to reproduce
When executed, the payload causes the application to render an HTML page containing an img tag that fails to load, triggering the onerror event handler which executes base64-decoded JavaScript, demonstrating successful XSS execution in the victim's browser. Mitigations
ImpactThe vulnerability requires no special privileges and can be exploited by getting a victim to visit a crafted URL. The impact is high as it allows arbitrary JavaScript execution in victims' browsers, potentially exposing sensitive data or enabling account takeover through session theft. Affected versions
0.4.1
0.4.2
0.4.3
0.4.4
0.4.4.post1
0.4.4.post2
0.4.5
0.4.6
0.4.6.post1
0.4.6.post2
0.4.7
0.4.8
+ 76 more Show less
0.5.0
0.5.1
0.6.0
0.6.1
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.4.post0
0.7.4.post1
0.7.5.post1
0.7.5.post2
0.8.0
0.8.0.post0
0.8.1
0.8.1.post0
0.8.2
0.8.2.post0
0.9.0
0.9.0.post2
0.9.0.post3
0.9.0.post4
0.9.0.post5
0.9.1
0.9.1.post0
0.9.1.post1
0.9.1.post2
1.0.0
1.0.0.post0
1.0.0.post1
1.0.0.post2
1.0.0.post3
1.0.1
1.0.2
1.0.2.post0
1.1.0
1.1.0rc0
1.1.1
1.10.0
1.10.0.post0
1.10.1
1.11.0
1.12.0
1.12.0.post0
1.12.1
1.13.0
1.13.1
1.14.0
1.14.0.post0
1.15.0
1.2
1.3
1.3.post0
1.3.post1
1.4
1.4.1
1.4.1.post0
1.4.1.post1
1.5.0
1.5.0.post0
1.6.0
1.7.0
1.7.1
1.7.2
1.7.3
1.8.0
1.8.1
1.8.2
1.8.2.post0
1.8.2.post1
1.9.0
1.9.1
1.9.1.post0
1.9.2
1.9.2.post0
Fixed in
1.16.0
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-47783
GHSA-8jhr-wpcm-hh4h
PYSEC-2025-124
May 15, 2025
label-studio vulnerable to Cross-Site Scripting (Reflected) via the label_config parameter.
High
Network
Low
None
SummaryThe vulnerability allows an attacker to inject a malicious script into the context of a web page, which can lead to data theft, unauthorized actions on behalf of the user, and other attacks. DetailsThe vulnerability is reproducible when sending a properly formatted request to the
The vulnerability is specifically located in line 57, where HttpResponse is used.
PoCSend the following request after changing the
Or you can create a vulnerable HTML page by changing
Impact
Affected versions
0.4.1
0.4.2
0.4.3
0.4.4
0.4.4.post1
0.4.4.post2
0.4.5
0.4.6
0.4.6.post1
0.4.6.post2
0.4.7
0.4.8
+ 78 more Show less
0.5.0
0.5.1
0.6.0
0.6.1
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.4.post0
0.7.4.post1
0.7.5.post1
0.7.5.post2
0.8.0
0.8.0.post0
0.8.1
0.8.1.post0
0.8.2
0.8.2.post0
0.9.0
0.9.0.post2
0.9.0.post3
0.9.0.post4
0.9.0.post5
0.9.1
0.9.1.post0
0.9.1.post1
0.9.1.post2
1.0.0
1.0.0.post0
1.0.0.post1
1.0.0.post2
1.0.0.post3
1.0.1
1.0.2
1.0.2.post0
1.1.0
1.1.0rc0
1.1.1
1.10.0
1.10.0.post0
1.10.1
1.11.0
1.12.0
1.12.0.post0
1.12.1
1.13.0
1.13.1
1.14.0
1.14.0.post0
1.15.0
1.16.0
1.17.0
1.2
1.3
1.3.post0
1.3.post1
1.4
1.4.1
1.4.1.post0
1.4.1.post1
1.5.0
1.5.0.post0
1.6.0
1.7.0
1.7.1
1.7.2
1.7.3
1.8.0
1.8.1
1.8.2
1.8.2.post0
1.8.2.post1
1.9.0
1.9.1
1.9.1.post0
1.9.2
1.9.2.post0
Fixed in
1.18.0
References
Updated Jun 06, 2026 · Source: OSV.dev
CVE-2024-26152
PYSEC-2024-249
GHSA-6xv9-957j-qfhg
Feb 22, 2024
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
SummaryOn all Label Studio versions prior to 1.11.0, data imported via file upload feature is not properly sanitized prior to being rendered within a DetailsNeed permission to use the "data import" function. This was reproduced on Label Studio 1.10.1. PoC
The following are the contents of the files used in the PoC
ImpactMalicious scripts can be injected into the code, and when linked with vulnerabilities such as CSRF, it can cause even greater damage. In particular, It can become a source of further attacks, especially when linked to social engineering. Affected versions
0.4.1
0.4.2
0.4.3
0.4.4
0.4.4.post1
0.4.4.post2
0.4.5
0.4.6
0.4.6.post1
0.4.6.post2
0.4.7
0.4.8
+ 113 more Show less
0.5.0
0.5.1
0.6.0
0.6.1
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.4.post0
0.7.4.post1
0.7.5.post1
0.7.5.post2
0.8.0
0.8.0.post0
0.8.1
0.8.1.post0
0.8.2
0.8.2.post0
0.9.0
0.9.0.post2
0.9.0.post3
0.9.0.post4
0.9.0.post5
0.9.1
0.9.1.post0
0.9.1.post1
0.9.1.post2
1.0.0
1.0.0.post0
1.0.0.post1
1.0.0.post2
1.0.0.post3
1.0.1
1.0.2
1.0.2.post0
1.1.0
1.1.0rc0
1.1.1
1.10.0
1.10.0.post0
1.10.1
1.2
1.3
1.3.post0
1.3.post1
1.4
1.4.1
1.4.1.post0
1.4.1.post1
1.5.0
1.5.0.post0
1.6.0
1.7.0
1.7.1
1.7.2
1.7.3
1.8.0
1.8.1
1.8.2
1.8.2.post0
1.8.2.post1
1.9.0
1.9.1
1.9.1.post0
1.9.2
1.9.2.post0
v1.4.1
v1.4.0
v1.3.0
v1.2.0
v1.1.1
v1.1.0
v1.0.2
v1.0.1
v1.0.0
v0.9.1.post1
v0.9.1.post0
v0.9.0.post5
v0.9.0.post4
v0.9.0.post3
v0.9.0
v0.8.2
v0.8.1
v0.8.0
v0.7.5.post0
v0.7.3
v0.7.2
v0.7.1
v0.7.0
v0.6.1
v0.6.0
v0.5.1
v0.4.8
v0.4.7
v0.4.6
v0.4.5
v0.4.4
v0.4.0
v0.3.0
v0.2.2
v.0.2.1-8
v.0.2.1-5
v.0.2.1-4
v.0.2.1-3
v.0.2.1-2
v.0.2.0
v.0.1.6
v.0.1.5
v.0.1.4
v.0.1.2
v.0.1.1
v.0.1.0
Fixed in
1.11.0
References
Updated Jun 10, 2026 · Source: OSV.dev
CVE-2023-47116
GHSA-p59w-9gqw-wj8r
PYSEC-2024-127
Jan 31, 2024
Label Studio SSRF on Import Bypassing `SSRF_PROTECTION_ENABLED` Protections
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
IntroductionThis write-up describes a vulnerability found in Label Studio, a popular open source data labeling tool. The vulnerability affects all versions of Label Studio prior to OverviewLabel Studio's SSRF protections that can be enabled by setting the DescriptionThe following
The
The issue here is the SSRF validation is only performed before the request is sent, and does not validate the destination IP address. Therefore, an attacker can either redirect the request or perform a DNS rebinding attack to bypass this protection. Proof of ConceptBoth the HTTP redirection and DNS rebinding methods for bypassing Label Studio's SSRF protections are explained below. HTTP RedirectionThe python
DNS Rebinding AttackDNS rebinding can bypass SSRF protections by resolving to an external IP address for the first resolution, but when the request is sent resolves to an internal IP address that is blocked. For an example, the domain ImpactSSRF vulnerabilities pose a significant risk on cloud environments, since instance credentials are managed by internal web APIs. An attacker can bypass Label Studio's SSRF protections to access internal web servers and partially compromise the confidentiality of those internal servers. Remediation Advice
Discovered
Affected versions
0.4.1
0.4.2
0.4.3
0.4.4
0.4.4.post1
0.4.4.post2
0.4.5
0.4.6
0.4.6.post1
0.4.6.post2
0.4.7
0.4.8
+ 67 more Show less
0.5.0
0.5.1
0.6.0
0.6.1
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.4.post0
0.7.4.post1
0.7.5.post1
0.7.5.post2
0.8.0
0.8.0.post0
0.8.1
0.8.1.post0
0.8.2
0.8.2.post0
0.9.0
0.9.0.post2
0.9.0.post3
0.9.0.post4
0.9.0.post5
0.9.1
0.9.1.post0
0.9.1.post1
0.9.1.post2
1.0.0
1.0.0.post0
1.0.0.post1
1.0.0.post2
1.0.0.post3
1.0.1
1.0.2
1.0.2.post0
1.1.0
1.1.0rc0
1.1.1
1.10.0
1.10.0.post0
1.10.1
1.2
1.3
1.3.post0
1.3.post1
1.4
1.4.1
1.4.1.post0
1.4.1.post1
1.5.0
1.5.0.post0
1.6.0
1.7.0
1.7.1
1.7.2
1.7.3
1.8.0
1.8.1
1.8.2
1.8.2.post0
1.8.2.post1
1.9.0
1.9.1
1.9.1.post0
1.9.2
1.9.2.post0
Fixed in
1.11.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-23633
GHSA-fq23-g58m-799r
PYSEC-2024-128
Jan 24, 2024
Cross-site Scripting Vulnerability on Data Import
4.7
/ 10
Medium
Network
Low
None
Required
Changed
Low
None
None
IntroductionThis write-up describes a vulnerability found in Label Studio, a popular open source data labeling tool. The vulnerability affects all versions of Label Studio prior to OverviewLabel Studio had a remote import feature allowed users to import data from a remote web source, that was downloaded and could be viewed on the website. This feature could had been abused to download a HTML file that executed malicious JavaScript code in the context of the Label Studio website. DescriptionThe following code snippet in Label Studio showed that is a URL passed the SSRF verification checks, the contents of the file would be downloaded using the filename in the URL.
The downloaded file path could then be retrieved by sending a request to
Since the Proof of ConceptBelow were the steps to recreate this issue:
ImpactExecuting arbitrary JavaScript could result in an attacker performing malicious actions on Label Studio users if they visit the crafted avatar image. For an example, an attacker can craft a JavaScript payload that adds a new Django Super Administrator user if a Django administrator visits the image. Remediation Advice
Discovered
Affected versions
0.4.1
0.4.2
0.4.3
0.4.4
0.4.4.post1
0.4.4.post2
0.4.5
0.4.6
0.4.6.post1
0.4.6.post2
0.4.7
0.4.8
+ 66 more Show less
0.5.0
0.5.1
0.6.0
0.6.1
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.4.post0
0.7.4.post1
0.7.5.post1
0.7.5.post2
0.8.0
0.8.0.post0
0.8.1
0.8.1.post0
0.8.2
0.8.2.post0
0.9.0
0.9.0.post2
0.9.0.post3
0.9.0.post4
0.9.0.post5
0.9.1
0.9.1.post0
0.9.1.post1
0.9.1.post2
1.0.0
1.0.0.post0
1.0.0.post1
1.0.0.post2
1.0.0.post3
1.0.1
1.0.2
1.0.2.post0
1.1.0
1.1.0rc0
1.1.1
1.10.0
1.10.0.post0
1.2
1.3
1.3.post0
1.3.post1
1.4
1.4.1
1.4.1.post0
1.4.1.post1
1.5.0
1.5.0.post0
1.6.0
1.7.0
1.7.1
1.7.2
1.7.3
1.8.0
1.8.1
1.8.2
1.8.2.post0
1.8.2.post1
1.9.0
1.9.1
1.9.1.post0
1.9.2
1.9.2.post0
Fixed in
1.10.1
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2023-47115
GHSA-q68h-xwq5-mm7x
PYSEC-2024-126
Jan 24, 2024
Cross-site Scripting Vulnerability on Avatar Upload
7.1
/ 10
High
Network
Low
None
Required
Changed
Low
Low
Low
IntroductionThis write-up describes a vulnerability found in Label Studio, a popular open source data labeling tool. The vulnerability affects all versions of Label Studio prior to OverviewLabel Studio has a cross-site scripting (XSS) vulnerability that could be exploited when an authenticated user uploads a crafted image file for their avatar that gets rendered as a HTML file on the website. DescriptionThe following code snippet in Label Studio shows that the only verification check is that the file is an image by extracting the dimensions from the file.
Label Studio serves avatar images using Django's built-in
The issue with the Django Proof of ConceptBelow are the steps to reproduce this issue and execute JavaScript code in the context of the Label Studio website.
ImpactExecuting arbitrary JavaScript could result in an attacker performing malicious actions on Label Studio users if they visit the crafted avatar image. For an example, an attacker can craft a JavaScript payload that adds a new Django Super Administrator user if a Django administrator visits the image. Remediation Advice
Discovered
Affected versions
0.4.1
0.4.2
0.4.3
0.4.4
0.4.4.post1
0.4.4.post2
0.4.5
0.4.6
0.4.6.post1
0.4.6.post2
0.4.7
0.4.8
+ 62 more Show less
0.5.0
0.5.1
0.6.0
0.6.1
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.4.post0
0.7.4.post1
0.7.5.post1
0.7.5.post2
0.8.0
0.8.0.post0
0.8.1
0.8.1.post0
0.8.2
0.8.2.post0
0.9.0
0.9.0.post2
0.9.0.post3
0.9.0.post4
0.9.0.post5
0.9.1
0.9.1.post0
0.9.1.post1
0.9.1.post2
1.0.0
1.0.0.post0
1.0.0.post1
1.0.0.post2
1.0.0.post3
1.0.1
1.0.2
1.0.2.post0
1.1.0
1.1.0rc0
1.1.1
1.2
1.3
1.3.post0
1.3.post1
1.4
1.4.1
1.4.1.post0
1.4.1.post1
1.5.0
1.5.0.post0
1.6.0
1.7.0
1.7.1
1.7.2
1.7.3
1.8.0
1.8.1
1.8.2
1.8.2.post0
1.8.2.post1
1.9.0
1.9.1
1.9.1.post0
Fixed in
1.9.2
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2023-47117
GHSA-6hjj-gq77-j4qw
PYSEC-2023-275
Nov 14, 2023
Label Studio Object Relational Mapper Leak Vulnerability in Filtering Task
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
IntroductionThis write-up describes a vulnerability found in Label Studio, a popular open source data labeling tool. The vulnerability affects all versions of Label Studio prior to OverviewIn all current versions of Label Studio, the application allows users to insecurely set filters for filtering tasks. An attacker can construct a filter chain to filter tasks based on sensitive fields for all user accounts on the platform by exploiting Django's Object Relational Mapper (ORM). Since the results of query can be manipulated by the ORM filter, an attacker can leak these sensitive fields character by character. For an example, the following filter chain will task results by the password hash of an account on Label Studio.
For consistency, this type of vulnerability will be termed as ORM Leak in the rest of this disclosure. In addition, Label Studio had a hard coded secret key that an attacker can use to forge a session token of any user by exploiting this ORM Leak vulnerability to leak account password hashes. DescriptionThe following code snippet from the
These
The
The following code snippet of the
Finally, the
Proof of ConceptBelow are the steps to exploit about how to exploit this vulnerability to leak the password hash of an account on Label Studio.
The following example GIF demonstrates exploiting this ORM Leak vulnerability to retrieve the password hash
ImpactThis vulnerability can be exploited to completely compromise the confidentiality of highly sensitive account information, such as account password hashes. For all versions Remediation Advice
Discovered
| ||
1.8.2
patch
9 CVEs
CVE-2026-22033
PYSEC-2026-1502
GHSA-2mq9-hm29-8qch
Jul 07, 2026
Label Studio is vulnerable to full account takeover by chaining Stored XSS + IDOR in User Profile via custom_hotkeys field
Critical
Network
Low
Low
None
PrologueThese vulnerabilities have been found and chained by DCODX-AI. Validation of the exploit chain has been confirmed manually. SummaryA persistent stored cross-site scripting (XSS) vulnerability exists in the custom_hotkeys functionality of the application. An authenticated attacker (or one who can trick a user/administrator into updating their custom_hotkeys) can inject JavaScript code that executes in other users’ browsers when those users load any page using the DetailsWithin
Here, user.custom_hotkeys is run through json_dumps_ensure_ascii (in In
The serializer allows
When another user loads a page using templates/base.html (for example PoC
Example request
Example response
ImpactExploitation impact:
Who is impacted:
Affected versions
0.4.1
0.4.2
0.4.3
0.4.4
0.4.4.post1
0.4.4.post2
0.4.5
0.4.6
0.4.6.post1
0.4.6.post2
0.4.7
0.4.8
+ 83 more Show less
0.5.0
0.5.1
0.6.0
0.6.1
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.4.post0
0.7.4.post1
0.7.5.post1
0.7.5.post2
0.8.0
0.8.0.post0
0.8.1
0.8.1.post0
0.8.2
0.8.2.post0
0.9.0
0.9.0.post2
0.9.0.post3
0.9.0.post4
0.9.0.post5
0.9.1
0.9.1.post0
0.9.1.post1
0.9.1.post2
1.0.0
1.0.0.post0
1.0.0.post1
1.0.0.post2
1.0.0.post3
1.0.1
1.0.2
1.0.2.post0
1.1.0
1.1.0rc0
1.1.1
1.10.0
1.10.0.post0
1.10.1
1.11.0
1.12.0
1.12.0.post0
1.12.1
1.13.0
1.13.1
1.14.0
1.14.0.post0
1.15.0
1.16.0
1.17.0
1.18.0
1.19.0
1.2
1.20.0
1.21.0
1.22.0
1.3
1.3.post0
1.3.post1
1.4
1.4.1
1.4.1.post0
1.4.1.post1
1.5.0
1.5.0.post0
1.6.0
1.7.0
1.7.1
1.7.2
1.7.3
1.8.0
1.8.1
1.8.2
1.8.2.post0
1.8.2.post1
1.9.0
1.9.1
1.9.1.post0
1.9.2
1.9.2.post0
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-25297
PYSEC-2026-1503
GHSA-m238-fmcw-wh58
Jul 07, 2026
Label Studio allows Server-Side Request Forgery in the S3 Storage Endpoint
8.6
/ 10
High
Network
Low
None
None
Changed
High
None
None
DescriptionLabel Studio's S3 storage integration feature contains a Server-Side Request Forgery (SSRF) vulnerability in its endpoint configuration. When creating an S3 storage connection, the application allows users to specify a custom S3 endpoint URL via the s3_endpoint parameter. This endpoint URL is passed directly to the boto3 AWS SDK without proper validation or restrictions on the protocol or destination. The vulnerability allows an attacker to make the application send HTTP requests to arbitrary internal services by specifying them as the S3 endpoint. When the storage sync operation is triggered, the application attempts to make S3 API calls to the specified endpoint, effectively making HTTP requests to the target service and returning the response in error messages. This SSRF vulnerability enables attackers to bypass network segmentation and access internal services that should not be accessible from the external network. The vulnerability is particularly severe because error messages from failed requests contain the full response body, allowing data exfiltration from internal services. Steps to reproduce
The application will attempt to connect to the specified endpoint URL as if it were an S3 service. When the request fails due to invalid S3 API responses, the error message will contain the raw response from the internal service, allowing access to internal resources. Mitigations
ImpactThis vulnerability has high severity as it allows authenticated users to make requests to arbitrary internal services from the application server, potentially exposing sensitive internal resources and bypassing network segmentation. The inclusion of response data in error messages makes this particularly effective for data exfiltration. Affected versions
0.4.1
0.4.2
0.4.3
0.4.4
0.4.4.post1
0.4.4.post2
0.4.5
0.4.6
0.4.6.post1
0.4.6.post2
0.4.7
0.4.8
+ 76 more Show less
0.5.0
0.5.1
0.6.0
0.6.1
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.4.post0
0.7.4.post1
0.7.5.post1
0.7.5.post2
0.8.0
0.8.0.post0
0.8.1
0.8.1.post0
0.8.2
0.8.2.post0
0.9.0
0.9.0.post2
0.9.0.post3
0.9.0.post4
0.9.0.post5
0.9.1
0.9.1.post0
0.9.1.post1
0.9.1.post2
1.0.0
1.0.0.post0
1.0.0.post1
1.0.0.post2
1.0.0.post3
1.0.1
1.0.2
1.0.2.post0
1.1.0
1.1.0rc0
1.1.1
1.10.0
1.10.0.post0
1.10.1
1.11.0
1.12.0
1.12.0.post0
1.12.1
1.13.0
1.13.1
1.14.0
1.14.0.post0
1.15.0
1.2
1.3
1.3.post0
1.3.post1
1.4
1.4.1
1.4.1.post0
1.4.1.post1
1.5.0
1.5.0.post0
1.6.0
1.7.0
1.7.1
1.7.2
1.7.3
1.8.0
1.8.1
1.8.2
1.8.2.post0
1.8.2.post1
1.9.0
1.9.1
1.9.1.post0
1.9.2
1.9.2.post0
Fixed in
1.16.0
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-25296
PYSEC-2026-1504
GHSA-wpq5-3366-mqw4
Jul 07, 2026
Label Studio allows Cross-Site Scripting (XSS) via GET request to `/projects/upload-example` endpoint
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
DescriptionLabel Studio's The vulnerability exists because the upload-example endpoint renders user-provided HTML content without proper sanitization on a GET request. This allows attackers to inject and execute arbitrary JavaScript in victims' browsers by getting them to visit a maliciously crafted URL. This is considered vulnerable because it enables attackers to execute JavaScript in victims' contexts, potentially allowing theft of sensitive data, session hijacking, or other malicious actions. Steps to reproduce
When executed, the payload causes the application to render an HTML page containing an img tag that fails to load, triggering the onerror event handler which executes base64-decoded JavaScript, demonstrating successful XSS execution in the victim's browser. Mitigations
ImpactThe vulnerability requires no special privileges and can be exploited by getting a victim to visit a crafted URL. The impact is high as it allows arbitrary JavaScript execution in victims' browsers, potentially exposing sensitive data or enabling account takeover through session theft. Affected versions
0.4.1
0.4.2
0.4.3
0.4.4
0.4.4.post1
0.4.4.post2
0.4.5
0.4.6
0.4.6.post1
0.4.6.post2
0.4.7
0.4.8
+ 76 more Show less
0.5.0
0.5.1
0.6.0
0.6.1
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.4.post0
0.7.4.post1
0.7.5.post1
0.7.5.post2
0.8.0
0.8.0.post0
0.8.1
0.8.1.post0
0.8.2
0.8.2.post0
0.9.0
0.9.0.post2
0.9.0.post3
0.9.0.post4
0.9.0.post5
0.9.1
0.9.1.post0
0.9.1.post1
0.9.1.post2
1.0.0
1.0.0.post0
1.0.0.post1
1.0.0.post2
1.0.0.post3
1.0.1
1.0.2
1.0.2.post0
1.1.0
1.1.0rc0
1.1.1
1.10.0
1.10.0.post0
1.10.1
1.11.0
1.12.0
1.12.0.post0
1.12.1
1.13.0
1.13.1
1.14.0
1.14.0.post0
1.15.0
1.2
1.3
1.3.post0
1.3.post1
1.4
1.4.1
1.4.1.post0
1.4.1.post1
1.5.0
1.5.0.post0
1.6.0
1.7.0
1.7.1
1.7.2
1.7.3
1.8.0
1.8.1
1.8.2
1.8.2.post0
1.8.2.post1
1.9.0
1.9.1
1.9.1.post0
1.9.2
1.9.2.post0
Fixed in
1.16.0
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-47783
GHSA-8jhr-wpcm-hh4h
PYSEC-2025-124
May 15, 2025
label-studio vulnerable to Cross-Site Scripting (Reflected) via the label_config parameter.
High
Network
Low
None
SummaryThe vulnerability allows an attacker to inject a malicious script into the context of a web page, which can lead to data theft, unauthorized actions on behalf of the user, and other attacks. DetailsThe vulnerability is reproducible when sending a properly formatted request to the
The vulnerability is specifically located in line 57, where HttpResponse is used.
PoCSend the following request after changing the
Or you can create a vulnerable HTML page by changing
Impact
Affected versions
0.4.1
0.4.2
0.4.3
0.4.4
0.4.4.post1
0.4.4.post2
0.4.5
0.4.6
0.4.6.post1
0.4.6.post2
0.4.7
0.4.8
+ 78 more Show less
0.5.0
0.5.1
0.6.0
0.6.1
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.4.post0
0.7.4.post1
0.7.5.post1
0.7.5.post2
0.8.0
0.8.0.post0
0.8.1
0.8.1.post0
0.8.2
0.8.2.post0
0.9.0
0.9.0.post2
0.9.0.post3
0.9.0.post4
0.9.0.post5
0.9.1
0.9.1.post0
0.9.1.post1
0.9.1.post2
1.0.0
1.0.0.post0
1.0.0.post1
1.0.0.post2
1.0.0.post3
1.0.1
1.0.2
1.0.2.post0
1.1.0
1.1.0rc0
1.1.1
1.10.0
1.10.0.post0
1.10.1
1.11.0
1.12.0
1.12.0.post0
1.12.1
1.13.0
1.13.1
1.14.0
1.14.0.post0
1.15.0
1.16.0
1.17.0
1.2
1.3
1.3.post0
1.3.post1
1.4
1.4.1
1.4.1.post0
1.4.1.post1
1.5.0
1.5.0.post0
1.6.0
1.7.0
1.7.1
1.7.2
1.7.3
1.8.0
1.8.1
1.8.2
1.8.2.post0
1.8.2.post1
1.9.0
1.9.1
1.9.1.post0
1.9.2
1.9.2.post0
Fixed in
1.18.0
References
Updated Jun 06, 2026 · Source: OSV.dev
CVE-2024-26152
PYSEC-2024-249
GHSA-6xv9-957j-qfhg
Feb 22, 2024
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
SummaryOn all Label Studio versions prior to 1.11.0, data imported via file upload feature is not properly sanitized prior to being rendered within a DetailsNeed permission to use the "data import" function. This was reproduced on Label Studio 1.10.1. PoC
The following are the contents of the files used in the PoC
ImpactMalicious scripts can be injected into the code, and when linked with vulnerabilities such as CSRF, it can cause even greater damage. In particular, It can become a source of further attacks, especially when linked to social engineering. Affected versions
0.4.1
0.4.2
0.4.3
0.4.4
0.4.4.post1
0.4.4.post2
0.4.5
0.4.6
0.4.6.post1
0.4.6.post2
0.4.7
0.4.8
+ 113 more Show less
0.5.0
0.5.1
0.6.0
0.6.1
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.4.post0
0.7.4.post1
0.7.5.post1
0.7.5.post2
0.8.0
0.8.0.post0
0.8.1
0.8.1.post0
0.8.2
0.8.2.post0
0.9.0
0.9.0.post2
0.9.0.post3
0.9.0.post4
0.9.0.post5
0.9.1
0.9.1.post0
0.9.1.post1
0.9.1.post2
1.0.0
1.0.0.post0
1.0.0.post1
1.0.0.post2
1.0.0.post3
1.0.1
1.0.2
1.0.2.post0
1.1.0
1.1.0rc0
1.1.1
1.10.0
1.10.0.post0
1.10.1
1.2
1.3
1.3.post0
1.3.post1
1.4
1.4.1
1.4.1.post0
1.4.1.post1
1.5.0
1.5.0.post0
1.6.0
1.7.0
1.7.1
1.7.2
1.7.3
1.8.0
1.8.1
1.8.2
1.8.2.post0
1.8.2.post1
1.9.0
1.9.1
1.9.1.post0
1.9.2
1.9.2.post0
v1.4.1
v1.4.0
v1.3.0
v1.2.0
v1.1.1
v1.1.0
v1.0.2
v1.0.1
v1.0.0
v0.9.1.post1
v0.9.1.post0
v0.9.0.post5
v0.9.0.post4
v0.9.0.post3
v0.9.0
v0.8.2
v0.8.1
v0.8.0
v0.7.5.post0
v0.7.3
v0.7.2
v0.7.1
v0.7.0
v0.6.1
v0.6.0
v0.5.1
v0.4.8
v0.4.7
v0.4.6
v0.4.5
v0.4.4
v0.4.0
v0.3.0
v0.2.2
v.0.2.1-8
v.0.2.1-5
v.0.2.1-4
v.0.2.1-3
v.0.2.1-2
v.0.2.0
v.0.1.6
v.0.1.5
v.0.1.4
v.0.1.2
v.0.1.1
v.0.1.0
Fixed in
1.11.0
References
Updated Jun 10, 2026 · Source: OSV.dev
CVE-2023-47116
GHSA-p59w-9gqw-wj8r
PYSEC-2024-127
Jan 31, 2024
Label Studio SSRF on Import Bypassing `SSRF_PROTECTION_ENABLED` Protections
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
IntroductionThis write-up describes a vulnerability found in Label Studio, a popular open source data labeling tool. The vulnerability affects all versions of Label Studio prior to OverviewLabel Studio's SSRF protections that can be enabled by setting the DescriptionThe following
The
The issue here is the SSRF validation is only performed before the request is sent, and does not validate the destination IP address. Therefore, an attacker can either redirect the request or perform a DNS rebinding attack to bypass this protection. Proof of ConceptBoth the HTTP redirection and DNS rebinding methods for bypassing Label Studio's SSRF protections are explained below. HTTP RedirectionThe python
DNS Rebinding AttackDNS rebinding can bypass SSRF protections by resolving to an external IP address for the first resolution, but when the request is sent resolves to an internal IP address that is blocked. For an example, the domain ImpactSSRF vulnerabilities pose a significant risk on cloud environments, since instance credentials are managed by internal web APIs. An attacker can bypass Label Studio's SSRF protections to access internal web servers and partially compromise the confidentiality of those internal servers. Remediation Advice
Discovered
Affected versions
0.4.1
0.4.2
0.4.3
0.4.4
0.4.4.post1
0.4.4.post2
0.4.5
0.4.6
0.4.6.post1
0.4.6.post2
0.4.7
0.4.8
+ 67 more Show less
0.5.0
0.5.1
0.6.0
0.6.1
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.4.post0
0.7.4.post1
0.7.5.post1
0.7.5.post2
0.8.0
0.8.0.post0
0.8.1
0.8.1.post0
0.8.2
0.8.2.post0
0.9.0
0.9.0.post2
0.9.0.post3
0.9.0.post4
0.9.0.post5
0.9.1
0.9.1.post0
0.9.1.post1
0.9.1.post2
1.0.0
1.0.0.post0
1.0.0.post1
1.0.0.post2
1.0.0.post3
1.0.1
1.0.2
1.0.2.post0
1.1.0
1.1.0rc0
1.1.1
1.10.0
1.10.0.post0
1.10.1
1.2
1.3
1.3.post0
1.3.post1
1.4
1.4.1
1.4.1.post0
1.4.1.post1
1.5.0
1.5.0.post0
1.6.0
1.7.0
1.7.1
1.7.2
1.7.3
1.8.0
1.8.1
1.8.2
1.8.2.post0
1.8.2.post1
1.9.0
1.9.1
1.9.1.post0
1.9.2
1.9.2.post0
Fixed in
1.11.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-23633
GHSA-fq23-g58m-799r
PYSEC-2024-128
Jan 24, 2024
Cross-site Scripting Vulnerability on Data Import
4.7
/ 10
Medium
Network
Low
None
Required
Changed
Low
None
None
IntroductionThis write-up describes a vulnerability found in Label Studio, a popular open source data labeling tool. The vulnerability affects all versions of Label Studio prior to OverviewLabel Studio had a remote import feature allowed users to import data from a remote web source, that was downloaded and could be viewed on the website. This feature could had been abused to download a HTML file that executed malicious JavaScript code in the context of the Label Studio website. DescriptionThe following code snippet in Label Studio showed that is a URL passed the SSRF verification checks, the contents of the file would be downloaded using the filename in the URL.
The downloaded file path could then be retrieved by sending a request to
Since the Proof of ConceptBelow were the steps to recreate this issue:
ImpactExecuting arbitrary JavaScript could result in an attacker performing malicious actions on Label Studio users if they visit the crafted avatar image. For an example, an attacker can craft a JavaScript payload that adds a new Django Super Administrator user if a Django administrator visits the image. Remediation Advice
Discovered
Affected versions
0.4.1
0.4.2
0.4.3
0.4.4
0.4.4.post1
0.4.4.post2
0.4.5
0.4.6
0.4.6.post1
0.4.6.post2
0.4.7
0.4.8
+ 66 more Show less
0.5.0
0.5.1
0.6.0
0.6.1
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.4.post0
0.7.4.post1
0.7.5.post1
0.7.5.post2
0.8.0
0.8.0.post0
0.8.1
0.8.1.post0
0.8.2
0.8.2.post0
0.9.0
0.9.0.post2
0.9.0.post3
0.9.0.post4
0.9.0.post5
0.9.1
0.9.1.post0
0.9.1.post1
0.9.1.post2
1.0.0
1.0.0.post0
1.0.0.post1
1.0.0.post2
1.0.0.post3
1.0.1
1.0.2
1.0.2.post0
1.1.0
1.1.0rc0
1.1.1
1.10.0
1.10.0.post0
1.2
1.3
1.3.post0
1.3.post1
1.4
1.4.1
1.4.1.post0
1.4.1.post1
1.5.0
1.5.0.post0
1.6.0
1.7.0
1.7.1
1.7.2
1.7.3
1.8.0
1.8.1
1.8.2
1.8.2.post0
1.8.2.post1
1.9.0
1.9.1
1.9.1.post0
1.9.2
1.9.2.post0
Fixed in
1.10.1
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2023-47115
GHSA-q68h-xwq5-mm7x
PYSEC-2024-126
Jan 24, 2024
Cross-site Scripting Vulnerability on Avatar Upload
7.1
/ 10
High
Network
Low
None
Required
Changed
Low
Low
Low
IntroductionThis write-up describes a vulnerability found in Label Studio, a popular open source data labeling tool. The vulnerability affects all versions of Label Studio prior to OverviewLabel Studio has a cross-site scripting (XSS) vulnerability that could be exploited when an authenticated user uploads a crafted image file for their avatar that gets rendered as a HTML file on the website. DescriptionThe following code snippet in Label Studio shows that the only verification check is that the file is an image by extracting the dimensions from the file.
Label Studio serves avatar images using Django's built-in
The issue with the Django Proof of ConceptBelow are the steps to reproduce this issue and execute JavaScript code in the context of the Label Studio website.
ImpactExecuting arbitrary JavaScript could result in an attacker performing malicious actions on Label Studio users if they visit the crafted avatar image. For an example, an attacker can craft a JavaScript payload that adds a new Django Super Administrator user if a Django administrator visits the image. Remediation Advice
Discovered
Affected versions
0.4.1
0.4.2
0.4.3
0.4.4
0.4.4.post1
0.4.4.post2
0.4.5
0.4.6
0.4.6.post1
0.4.6.post2
0.4.7
0.4.8
+ 62 more Show less
0.5.0
0.5.1
0.6.0
0.6.1
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.4.post0
0.7.4.post1
0.7.5.post1
0.7.5.post2
0.8.0
0.8.0.post0
0.8.1
0.8.1.post0
0.8.2
0.8.2.post0
0.9.0
0.9.0.post2
0.9.0.post3
0.9.0.post4
0.9.0.post5
0.9.1
0.9.1.post0
0.9.1.post1
0.9.1.post2
1.0.0
1.0.0.post0
1.0.0.post1
1.0.0.post2
1.0.0.post3
1.0.1
1.0.2
1.0.2.post0
1.1.0
1.1.0rc0
1.1.1
1.2
1.3
1.3.post0
1.3.post1
1.4
1.4.1
1.4.1.post0
1.4.1.post1
1.5.0
1.5.0.post0
1.6.0
1.7.0
1.7.1
1.7.2
1.7.3
1.8.0
1.8.1
1.8.2
1.8.2.post0
1.8.2.post1
1.9.0
1.9.1
1.9.1.post0
Fixed in
1.9.2
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2023-47117
GHSA-6hjj-gq77-j4qw
PYSEC-2023-275
Nov 14, 2023
Label Studio Object Relational Mapper Leak Vulnerability in Filtering Task
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
IntroductionThis write-up describes a vulnerability found in Label Studio, a popular open source data labeling tool. The vulnerability affects all versions of Label Studio prior to OverviewIn all current versions of Label Studio, the application allows users to insecurely set filters for filtering tasks. An attacker can construct a filter chain to filter tasks based on sensitive fields for all user accounts on the platform by exploiting Django's Object Relational Mapper (ORM). Since the results of query can be manipulated by the ORM filter, an attacker can leak these sensitive fields character by character. For an example, the following filter chain will task results by the password hash of an account on Label Studio.
For consistency, this type of vulnerability will be termed as ORM Leak in the rest of this disclosure. In addition, Label Studio had a hard coded secret key that an attacker can use to forge a session token of any user by exploiting this ORM Leak vulnerability to leak account password hashes. DescriptionThe following code snippet from the
These
The
The following code snippet of the
Finally, the
Proof of ConceptBelow are the steps to exploit about how to exploit this vulnerability to leak the password hash of an account on Label Studio.
The following example GIF demonstrates exploiting this ORM Leak vulnerability to retrieve the password hash
ImpactThis vulnerability can be exploited to completely compromise the confidentiality of highly sensitive account information, such as account password hashes. For all versions Remediation Advice
Discovered
| ||
1.8.1
patch
10 CVEs
CVE-2026-22033
PYSEC-2026-1502
GHSA-2mq9-hm29-8qch
Jul 07, 2026
Label Studio is vulnerable to full account takeover by chaining Stored XSS + IDOR in User Profile via custom_hotkeys field
Critical
Network
Low
Low
None
PrologueThese vulnerabilities have been found and chained by DCODX-AI. Validation of the exploit chain has been confirmed manually. SummaryA persistent stored cross-site scripting (XSS) vulnerability exists in the custom_hotkeys functionality of the application. An authenticated attacker (or one who can trick a user/administrator into updating their custom_hotkeys) can inject JavaScript code that executes in other users’ browsers when those users load any page using the DetailsWithin
Here, user.custom_hotkeys is run through json_dumps_ensure_ascii (in In
The serializer allows
When another user loads a page using templates/base.html (for example PoC
Example request
Example response
ImpactExploitation impact:
Who is impacted:
Affected versions
0.4.1
0.4.2
0.4.3
0.4.4
0.4.4.post1
0.4.4.post2
0.4.5
0.4.6
0.4.6.post1
0.4.6.post2
0.4.7
0.4.8
+ 83 more Show less
0.5.0
0.5.1
0.6.0
0.6.1
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.4.post0
0.7.4.post1
0.7.5.post1
0.7.5.post2
0.8.0
0.8.0.post0
0.8.1
0.8.1.post0
0.8.2
0.8.2.post0
0.9.0
0.9.0.post2
0.9.0.post3
0.9.0.post4
0.9.0.post5
0.9.1
0.9.1.post0
0.9.1.post1
0.9.1.post2
1.0.0
1.0.0.post0
1.0.0.post1
1.0.0.post2
1.0.0.post3
1.0.1
1.0.2
1.0.2.post0
1.1.0
1.1.0rc0
1.1.1
1.10.0
1.10.0.post0
1.10.1
1.11.0
1.12.0
1.12.0.post0
1.12.1
1.13.0
1.13.1
1.14.0
1.14.0.post0
1.15.0
1.16.0
1.17.0
1.18.0
1.19.0
1.2
1.20.0
1.21.0
1.22.0
1.3
1.3.post0
1.3.post1
1.4
1.4.1
1.4.1.post0
1.4.1.post1
1.5.0
1.5.0.post0
1.6.0
1.7.0
1.7.1
1.7.2
1.7.3
1.8.0
1.8.1
1.8.2
1.8.2.post0
1.8.2.post1
1.9.0
1.9.1
1.9.1.post0
1.9.2
1.9.2.post0
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-25297
PYSEC-2026-1503
GHSA-m238-fmcw-wh58
Jul 07, 2026
Label Studio allows Server-Side Request Forgery in the S3 Storage Endpoint
8.6
/ 10
High
Network
Low
None
None
Changed
High
None
None
DescriptionLabel Studio's S3 storage integration feature contains a Server-Side Request Forgery (SSRF) vulnerability in its endpoint configuration. When creating an S3 storage connection, the application allows users to specify a custom S3 endpoint URL via the s3_endpoint parameter. This endpoint URL is passed directly to the boto3 AWS SDK without proper validation or restrictions on the protocol or destination. The vulnerability allows an attacker to make the application send HTTP requests to arbitrary internal services by specifying them as the S3 endpoint. When the storage sync operation is triggered, the application attempts to make S3 API calls to the specified endpoint, effectively making HTTP requests to the target service and returning the response in error messages. This SSRF vulnerability enables attackers to bypass network segmentation and access internal services that should not be accessible from the external network. The vulnerability is particularly severe because error messages from failed requests contain the full response body, allowing data exfiltration from internal services. Steps to reproduce
The application will attempt to connect to the specified endpoint URL as if it were an S3 service. When the request fails due to invalid S3 API responses, the error message will contain the raw response from the internal service, allowing access to internal resources. Mitigations
ImpactThis vulnerability has high severity as it allows authenticated users to make requests to arbitrary internal services from the application server, potentially exposing sensitive internal resources and bypassing network segmentation. The inclusion of response data in error messages makes this particularly effective for data exfiltration. Affected versions
0.4.1
0.4.2
0.4.3
0.4.4
0.4.4.post1
0.4.4.post2
0.4.5
0.4.6
0.4.6.post1
0.4.6.post2
0.4.7
0.4.8
+ 76 more Show less
0.5.0
0.5.1
0.6.0
0.6.1
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.4.post0
0.7.4.post1
0.7.5.post1
0.7.5.post2
0.8.0
0.8.0.post0
0.8.1
0.8.1.post0
0.8.2
0.8.2.post0
0.9.0
0.9.0.post2
0.9.0.post3
0.9.0.post4
0.9.0.post5
0.9.1
0.9.1.post0
0.9.1.post1
0.9.1.post2
1.0.0
1.0.0.post0
1.0.0.post1
1.0.0.post2
1.0.0.post3
1.0.1
1.0.2
1.0.2.post0
1.1.0
1.1.0rc0
1.1.1
1.10.0
1.10.0.post0
1.10.1
1.11.0
1.12.0
1.12.0.post0
1.12.1
1.13.0
1.13.1
1.14.0
1.14.0.post0
1.15.0
1.2
1.3
1.3.post0
1.3.post1
1.4
1.4.1
1.4.1.post0
1.4.1.post1
1.5.0
1.5.0.post0
1.6.0
1.7.0
1.7.1
1.7.2
1.7.3
1.8.0
1.8.1
1.8.2
1.8.2.post0
1.8.2.post1
1.9.0
1.9.1
1.9.1.post0
1.9.2
1.9.2.post0
Fixed in
1.16.0
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-25296
PYSEC-2026-1504
GHSA-wpq5-3366-mqw4
Jul 07, 2026
Label Studio allows Cross-Site Scripting (XSS) via GET request to `/projects/upload-example` endpoint
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
DescriptionLabel Studio's The vulnerability exists because the upload-example endpoint renders user-provided HTML content without proper sanitization on a GET request. This allows attackers to inject and execute arbitrary JavaScript in victims' browsers by getting them to visit a maliciously crafted URL. This is considered vulnerable because it enables attackers to execute JavaScript in victims' contexts, potentially allowing theft of sensitive data, session hijacking, or other malicious actions. Steps to reproduce
When executed, the payload causes the application to render an HTML page containing an img tag that fails to load, triggering the onerror event handler which executes base64-decoded JavaScript, demonstrating successful XSS execution in the victim's browser. Mitigations
ImpactThe vulnerability requires no special privileges and can be exploited by getting a victim to visit a crafted URL. The impact is high as it allows arbitrary JavaScript execution in victims' browsers, potentially exposing sensitive data or enabling account takeover through session theft. Affected versions
0.4.1
0.4.2
0.4.3
0.4.4
0.4.4.post1
0.4.4.post2
0.4.5
0.4.6
0.4.6.post1
0.4.6.post2
0.4.7
0.4.8
+ 76 more Show less
0.5.0
0.5.1
0.6.0
0.6.1
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.4.post0
0.7.4.post1
0.7.5.post1
0.7.5.post2
0.8.0
0.8.0.post0
0.8.1
0.8.1.post0
0.8.2
0.8.2.post0
0.9.0
0.9.0.post2
0.9.0.post3
0.9.0.post4
0.9.0.post5
0.9.1
0.9.1.post0
0.9.1.post1
0.9.1.post2
1.0.0
1.0.0.post0
1.0.0.post1
1.0.0.post2
1.0.0.post3
1.0.1
1.0.2
1.0.2.post0
1.1.0
1.1.0rc0
1.1.1
1.10.0
1.10.0.post0
1.10.1
1.11.0
1.12.0
1.12.0.post0
1.12.1
1.13.0
1.13.1
1.14.0
1.14.0.post0
1.15.0
1.2
1.3
1.3.post0
1.3.post1
1.4
1.4.1
1.4.1.post0
1.4.1.post1
1.5.0
1.5.0.post0
1.6.0
1.7.0
1.7.1
1.7.2
1.7.3
1.8.0
1.8.1
1.8.2
1.8.2.post0
1.8.2.post1
1.9.0
1.9.1
1.9.1.post0
1.9.2
1.9.2.post0
Fixed in
1.16.0
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-47783
GHSA-8jhr-wpcm-hh4h
PYSEC-2025-124
May 15, 2025
label-studio vulnerable to Cross-Site Scripting (Reflected) via the label_config parameter.
High
Network
Low
None
SummaryThe vulnerability allows an attacker to inject a malicious script into the context of a web page, which can lead to data theft, unauthorized actions on behalf of the user, and other attacks. DetailsThe vulnerability is reproducible when sending a properly formatted request to the
The vulnerability is specifically located in line 57, where HttpResponse is used.
PoCSend the following request after changing the
Or you can create a vulnerable HTML page by changing
Impact
Affected versions
0.4.1
0.4.2
0.4.3
0.4.4
0.4.4.post1
0.4.4.post2
0.4.5
0.4.6
0.4.6.post1
0.4.6.post2
0.4.7
0.4.8
+ 78 more Show less
0.5.0
0.5.1
0.6.0
0.6.1
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.4.post0
0.7.4.post1
0.7.5.post1
0.7.5.post2
0.8.0
0.8.0.post0
0.8.1
0.8.1.post0
0.8.2
0.8.2.post0
0.9.0
0.9.0.post2
0.9.0.post3
0.9.0.post4
0.9.0.post5
0.9.1
0.9.1.post0
0.9.1.post1
0.9.1.post2
1.0.0
1.0.0.post0
1.0.0.post1
1.0.0.post2
1.0.0.post3
1.0.1
1.0.2
1.0.2.post0
1.1.0
1.1.0rc0
1.1.1
1.10.0
1.10.0.post0
1.10.1
1.11.0
1.12.0
1.12.0.post0
1.12.1
1.13.0
1.13.1
1.14.0
1.14.0.post0
1.15.0
1.16.0
1.17.0
1.2
1.3
1.3.post0
1.3.post1
1.4
1.4.1
1.4.1.post0
1.4.1.post1
1.5.0
1.5.0.post0
1.6.0
1.7.0
1.7.1
1.7.2
1.7.3
1.8.0
1.8.1
1.8.2
1.8.2.post0
1.8.2.post1
1.9.0
1.9.1
1.9.1.post0
1.9.2
1.9.2.post0
Fixed in
1.18.0
References
Updated Jun 06, 2026 · Source: OSV.dev
CVE-2024-26152
PYSEC-2024-249
GHSA-6xv9-957j-qfhg
Feb 22, 2024
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
SummaryOn all Label Studio versions prior to 1.11.0, data imported via file upload feature is not properly sanitized prior to being rendered within a DetailsNeed permission to use the "data import" function. This was reproduced on Label Studio 1.10.1. PoC
The following are the contents of the files used in the PoC
ImpactMalicious scripts can be injected into the code, and when linked with vulnerabilities such as CSRF, it can cause even greater damage. In particular, It can become a source of further attacks, especially when linked to social engineering. Affected versions
0.4.1
0.4.2
0.4.3
0.4.4
0.4.4.post1
0.4.4.post2
0.4.5
0.4.6
0.4.6.post1
0.4.6.post2
0.4.7
0.4.8
+ 113 more Show less
0.5.0
0.5.1
0.6.0
0.6.1
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.4.post0
0.7.4.post1
0.7.5.post1
0.7.5.post2
0.8.0
0.8.0.post0
0.8.1
0.8.1.post0
0.8.2
0.8.2.post0
0.9.0
0.9.0.post2
0.9.0.post3
0.9.0.post4
0.9.0.post5
0.9.1
0.9.1.post0
0.9.1.post1
0.9.1.post2
1.0.0
1.0.0.post0
1.0.0.post1
1.0.0.post2
1.0.0.post3
1.0.1
1.0.2
1.0.2.post0
1.1.0
1.1.0rc0
1.1.1
1.10.0
1.10.0.post0
1.10.1
1.2
1.3
1.3.post0
1.3.post1
1.4
1.4.1
1.4.1.post0
1.4.1.post1
1.5.0
1.5.0.post0
1.6.0
1.7.0
1.7.1
1.7.2
1.7.3
1.8.0
1.8.1
1.8.2
1.8.2.post0
1.8.2.post1
1.9.0
1.9.1
1.9.1.post0
1.9.2
1.9.2.post0
v1.4.1
v1.4.0
v1.3.0
v1.2.0
v1.1.1
v1.1.0
v1.0.2
v1.0.1
v1.0.0
v0.9.1.post1
v0.9.1.post0
v0.9.0.post5
v0.9.0.post4
v0.9.0.post3
v0.9.0
v0.8.2
v0.8.1
v0.8.0
v0.7.5.post0
v0.7.3
v0.7.2
v0.7.1
v0.7.0
v0.6.1
v0.6.0
v0.5.1
v0.4.8
v0.4.7
v0.4.6
v0.4.5
v0.4.4
v0.4.0
v0.3.0
v0.2.2
v.0.2.1-8
v.0.2.1-5
v.0.2.1-4
v.0.2.1-3
v.0.2.1-2
v.0.2.0
v.0.1.6
v.0.1.5
v.0.1.4
v.0.1.2
v.0.1.1
v.0.1.0
Fixed in
1.11.0
References
Updated Jun 10, 2026 · Source: OSV.dev
CVE-2023-47116
GHSA-p59w-9gqw-wj8r
PYSEC-2024-127
Jan 31, 2024
Label Studio SSRF on Import Bypassing `SSRF_PROTECTION_ENABLED` Protections
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
IntroductionThis write-up describes a vulnerability found in Label Studio, a popular open source data labeling tool. The vulnerability affects all versions of Label Studio prior to OverviewLabel Studio's SSRF protections that can be enabled by setting the DescriptionThe following
The
The issue here is the SSRF validation is only performed before the request is sent, and does not validate the destination IP address. Therefore, an attacker can either redirect the request or perform a DNS rebinding attack to bypass this protection. Proof of ConceptBoth the HTTP redirection and DNS rebinding methods for bypassing Label Studio's SSRF protections are explained below. HTTP RedirectionThe python
DNS Rebinding AttackDNS rebinding can bypass SSRF protections by resolving to an external IP address for the first resolution, but when the request is sent resolves to an internal IP address that is blocked. For an example, the domain ImpactSSRF vulnerabilities pose a significant risk on cloud environments, since instance credentials are managed by internal web APIs. An attacker can bypass Label Studio's SSRF protections to access internal web servers and partially compromise the confidentiality of those internal servers. Remediation Advice
Discovered
Affected versions
0.4.1
0.4.2
0.4.3
0.4.4
0.4.4.post1
0.4.4.post2
0.4.5
0.4.6
0.4.6.post1
0.4.6.post2
0.4.7
0.4.8
+ 67 more Show less
0.5.0
0.5.1
0.6.0
0.6.1
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.4.post0
0.7.4.post1
0.7.5.post1
0.7.5.post2
0.8.0
0.8.0.post0
0.8.1
0.8.1.post0
0.8.2
0.8.2.post0
0.9.0
0.9.0.post2
0.9.0.post3
0.9.0.post4
0.9.0.post5
0.9.1
0.9.1.post0
0.9.1.post1
0.9.1.post2
1.0.0
1.0.0.post0
1.0.0.post1
1.0.0.post2
1.0.0.post3
1.0.1
1.0.2
1.0.2.post0
1.1.0
1.1.0rc0
1.1.1
1.10.0
1.10.0.post0
1.10.1
1.2
1.3
1.3.post0
1.3.post1
1.4
1.4.1
1.4.1.post0
1.4.1.post1
1.5.0
1.5.0.post0
1.6.0
1.7.0
1.7.1
1.7.2
1.7.3
1.8.0
1.8.1
1.8.2
1.8.2.post0
1.8.2.post1
1.9.0
1.9.1
1.9.1.post0
1.9.2
1.9.2.post0
Fixed in
1.11.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-23633
GHSA-fq23-g58m-799r
PYSEC-2024-128
Jan 24, 2024
Cross-site Scripting Vulnerability on Data Import
4.7
/ 10
Medium
Network
Low
None
Required
Changed
Low
None
None
IntroductionThis write-up describes a vulnerability found in Label Studio, a popular open source data labeling tool. The vulnerability affects all versions of Label Studio prior to OverviewLabel Studio had a remote import feature allowed users to import data from a remote web source, that was downloaded and could be viewed on the website. This feature could had been abused to download a HTML file that executed malicious JavaScript code in the context of the Label Studio website. DescriptionThe following code snippet in Label Studio showed that is a URL passed the SSRF verification checks, the contents of the file would be downloaded using the filename in the URL.
The downloaded file path could then be retrieved by sending a request to
Since the Proof of ConceptBelow were the steps to recreate this issue:
ImpactExecuting arbitrary JavaScript could result in an attacker performing malicious actions on Label Studio users if they visit the crafted avatar image. For an example, an attacker can craft a JavaScript payload that adds a new Django Super Administrator user if a Django administrator visits the image. Remediation Advice
Discovered
Affected versions
0.4.1
0.4.2
0.4.3
0.4.4
0.4.4.post1
0.4.4.post2
0.4.5
0.4.6
0.4.6.post1
0.4.6.post2
0.4.7
0.4.8
+ 66 more Show less
0.5.0
0.5.1
0.6.0
0.6.1
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.4.post0
0.7.4.post1
0.7.5.post1
0.7.5.post2
0.8.0
0.8.0.post0
0.8.1
0.8.1.post0
0.8.2
0.8.2.post0
0.9.0
0.9.0.post2
0.9.0.post3
0.9.0.post4
0.9.0.post5
0.9.1
0.9.1.post0
0.9.1.post1
0.9.1.post2
1.0.0
1.0.0.post0
1.0.0.post1
1.0.0.post2
1.0.0.post3
1.0.1
1.0.2
1.0.2.post0
1.1.0
1.1.0rc0
1.1.1
1.10.0
1.10.0.post0
1.2
1.3
1.3.post0
1.3.post1
1.4
1.4.1
1.4.1.post0
1.4.1.post1
1.5.0
1.5.0.post0
1.6.0
1.7.0
1.7.1
1.7.2
1.7.3
1.8.0
1.8.1
1.8.2
1.8.2.post0
1.8.2.post1
1.9.0
1.9.1
1.9.1.post0
1.9.2
1.9.2.post0
Fixed in
1.10.1
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2023-47115
GHSA-q68h-xwq5-mm7x
PYSEC-2024-126
Jan 24, 2024
Cross-site Scripting Vulnerability on Avatar Upload
7.1
/ 10
High
Network
Low
None
Required
Changed
Low
Low
Low
IntroductionThis write-up describes a vulnerability found in Label Studio, a popular open source data labeling tool. The vulnerability affects all versions of Label Studio prior to OverviewLabel Studio has a cross-site scripting (XSS) vulnerability that could be exploited when an authenticated user uploads a crafted image file for their avatar that gets rendered as a HTML file on the website. DescriptionThe following code snippet in Label Studio shows that the only verification check is that the file is an image by extracting the dimensions from the file.
Label Studio serves avatar images using Django's built-in
The issue with the Django Proof of ConceptBelow are the steps to reproduce this issue and execute JavaScript code in the context of the Label Studio website.
ImpactExecuting arbitrary JavaScript could result in an attacker performing malicious actions on Label Studio users if they visit the crafted avatar image. For an example, an attacker can craft a JavaScript payload that adds a new Django Super Administrator user if a Django administrator visits the image. Remediation Advice
Discovered
Affected versions
0.4.1
0.4.2
0.4.3
0.4.4
0.4.4.post1
0.4.4.post2
0.4.5
0.4.6
0.4.6.post1
0.4.6.post2
0.4.7
0.4.8
+ 62 more Show less
0.5.0
0.5.1
0.6.0
0.6.1
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.4.post0
0.7.4.post1
0.7.5.post1
0.7.5.post2
0.8.0
0.8.0.post0
0.8.1
0.8.1.post0
0.8.2
0.8.2.post0
0.9.0
0.9.0.post2
0.9.0.post3
0.9.0.post4
0.9.0.post5
0.9.1
0.9.1.post0
0.9.1.post1
0.9.1.post2
1.0.0
1.0.0.post0
1.0.0.post1
1.0.0.post2
1.0.0.post3
1.0.1
1.0.2
1.0.2.post0
1.1.0
1.1.0rc0
1.1.1
1.2
1.3
1.3.post0
1.3.post1
1.4
1.4.1
1.4.1.post0
1.4.1.post1
1.5.0
1.5.0.post0
1.6.0
1.7.0
1.7.1
1.7.2
1.7.3
1.8.0
1.8.1
1.8.2
1.8.2.post0
1.8.2.post1
1.9.0
1.9.1
1.9.1.post0
Fixed in
1.9.2
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2023-47117
GHSA-6hjj-gq77-j4qw
PYSEC-2023-275
Nov 14, 2023
Label Studio Object Relational Mapper Leak Vulnerability in Filtering Task
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
IntroductionThis write-up describes a vulnerability found in Label Studio, a popular open source data labeling tool. The vulnerability affects all versions of Label Studio prior to OverviewIn all current versions of Label Studio, the application allows users to insecurely set filters for filtering tasks. An attacker can construct a filter chain to filter tasks based on sensitive fields for all user accounts on the platform by exploiting Django's Object Relational Mapper (ORM). Since the results of query can be manipulated by the ORM filter, an attacker can leak these sensitive fields character by character. For an example, the following filter chain will task results by the password hash of an account on Label Studio.
For consistency, this type of vulnerability will be termed as ORM Leak in the rest of this disclosure. In addition, Label Studio had a hard coded secret key that an attacker can use to forge a session token of any user by exploiting this ORM Leak vulnerability to leak account password hashes. DescriptionThe following code snippet from the
These
The
The following code snippet of the
Finally, the
Proof of ConceptBelow are the steps to exploit about how to exploit this vulnerability to leak the password hash of an account on Label Studio.
The following example GIF demonstrates exploiting this ORM Leak vulnerability to retrieve the password hash
ImpactThis vulnerability can be exploited to completely compromise the confidentiality of highly sensitive account information, such as account password hashes. For all versions Remediation Advice
Discovered
| ||
1.8.0
minor
10 CVEs
CVE-2026-22033
PYSEC-2026-1502
GHSA-2mq9-hm29-8qch
Jul 07, 2026
Label Studio is vulnerable to full account takeover by chaining Stored XSS + IDOR in User Profile via custom_hotkeys field
Critical
Network
Low
Low
None
PrologueThese vulnerabilities have been found and chained by DCODX-AI. Validation of the exploit chain has been confirmed manually. SummaryA persistent stored cross-site scripting (XSS) vulnerability exists in the custom_hotkeys functionality of the application. An authenticated attacker (or one who can trick a user/administrator into updating their custom_hotkeys) can inject JavaScript code that executes in other users’ browsers when those users load any page using the DetailsWithin
Here, user.custom_hotkeys is run through json_dumps_ensure_ascii (in In
The serializer allows
When another user loads a page using templates/base.html (for example PoC
Example request
Example response
ImpactExploitation impact:
Who is impacted:
Affected versions
0.4.1
0.4.2
0.4.3
0.4.4
0.4.4.post1
0.4.4.post2
0.4.5
0.4.6
0.4.6.post1
0.4.6.post2
0.4.7
0.4.8
+ 83 more Show less
0.5.0
0.5.1
0.6.0
0.6.1
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.4.post0
0.7.4.post1
0.7.5.post1
0.7.5.post2
0.8.0
0.8.0.post0
0.8.1
0.8.1.post0
0.8.2
0.8.2.post0
0.9.0
0.9.0.post2
0.9.0.post3
0.9.0.post4
0.9.0.post5
0.9.1
0.9.1.post0
0.9.1.post1
0.9.1.post2
1.0.0
1.0.0.post0
1.0.0.post1
1.0.0.post2
1.0.0.post3
1.0.1
1.0.2
1.0.2.post0
1.1.0
1.1.0rc0
1.1.1
1.10.0
1.10.0.post0
1.10.1
1.11.0
1.12.0
1.12.0.post0
1.12.1
1.13.0
1.13.1
1.14.0
1.14.0.post0
1.15.0
1.16.0
1.17.0
1.18.0
1.19.0
1.2
1.20.0
1.21.0
1.22.0
1.3
1.3.post0
1.3.post1
1.4
1.4.1
1.4.1.post0
1.4.1.post1
1.5.0
1.5.0.post0
1.6.0
1.7.0
1.7.1
1.7.2
1.7.3
1.8.0
1.8.1
1.8.2
1.8.2.post0
1.8.2.post1
1.9.0
1.9.1
1.9.1.post0
1.9.2
1.9.2.post0
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-25297
PYSEC-2026-1503
GHSA-m238-fmcw-wh58
Jul 07, 2026
Label Studio allows Server-Side Request Forgery in the S3 Storage Endpoint
8.6
/ 10
High
Network
Low
None
None
Changed
High
None
None
DescriptionLabel Studio's S3 storage integration feature contains a Server-Side Request Forgery (SSRF) vulnerability in its endpoint configuration. When creating an S3 storage connection, the application allows users to specify a custom S3 endpoint URL via the s3_endpoint parameter. This endpoint URL is passed directly to the boto3 AWS SDK without proper validation or restrictions on the protocol or destination. The vulnerability allows an attacker to make the application send HTTP requests to arbitrary internal services by specifying them as the S3 endpoint. When the storage sync operation is triggered, the application attempts to make S3 API calls to the specified endpoint, effectively making HTTP requests to the target service and returning the response in error messages. This SSRF vulnerability enables attackers to bypass network segmentation and access internal services that should not be accessible from the external network. The vulnerability is particularly severe because error messages from failed requests contain the full response body, allowing data exfiltration from internal services. Steps to reproduce
The application will attempt to connect to the specified endpoint URL as if it were an S3 service. When the request fails due to invalid S3 API responses, the error message will contain the raw response from the internal service, allowing access to internal resources. Mitigations
ImpactThis vulnerability has high severity as it allows authenticated users to make requests to arbitrary internal services from the application server, potentially exposing sensitive internal resources and bypassing network segmentation. The inclusion of response data in error messages makes this particularly effective for data exfiltration. Affected versions
0.4.1
0.4.2
0.4.3
0.4.4
0.4.4.post1
0.4.4.post2
0.4.5
0.4.6
0.4.6.post1
0.4.6.post2
0.4.7
0.4.8
+ 76 more Show less
0.5.0
0.5.1
0.6.0
0.6.1
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.4.post0
0.7.4.post1
0.7.5.post1
0.7.5.post2
0.8.0
0.8.0.post0
0.8.1
0.8.1.post0
0.8.2
0.8.2.post0
0.9.0
0.9.0.post2
0.9.0.post3
0.9.0.post4
0.9.0.post5
0.9.1
0.9.1.post0
0.9.1.post1
0.9.1.post2
1.0.0
1.0.0.post0
1.0.0.post1
1.0.0.post2
1.0.0.post3
1.0.1
1.0.2
1.0.2.post0
1.1.0
1.1.0rc0
1.1.1
1.10.0
1.10.0.post0
1.10.1
1.11.0
1.12.0
1.12.0.post0
1.12.1
1.13.0
1.13.1
1.14.0
1.14.0.post0
1.15.0
1.2
1.3
1.3.post0
1.3.post1
1.4
1.4.1
1.4.1.post0
1.4.1.post1
1.5.0
1.5.0.post0
1.6.0
1.7.0
1.7.1
1.7.2
1.7.3
1.8.0
1.8.1
1.8.2
1.8.2.post0
1.8.2.post1
1.9.0
1.9.1
1.9.1.post0
1.9.2
1.9.2.post0
Fixed in
1.16.0
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-25296
PYSEC-2026-1504
GHSA-wpq5-3366-mqw4
Jul 07, 2026
Label Studio allows Cross-Site Scripting (XSS) via GET request to `/projects/upload-example` endpoint
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
DescriptionLabel Studio's The vulnerability exists because the upload-example endpoint renders user-provided HTML content without proper sanitization on a GET request. This allows attackers to inject and execute arbitrary JavaScript in victims' browsers by getting them to visit a maliciously crafted URL. This is considered vulnerable because it enables attackers to execute JavaScript in victims' contexts, potentially allowing theft of sensitive data, session hijacking, or other malicious actions. Steps to reproduce
When executed, the payload causes the application to render an HTML page containing an img tag that fails to load, triggering the onerror event handler which executes base64-decoded JavaScript, demonstrating successful XSS execution in the victim's browser. Mitigations
ImpactThe vulnerability requires no special privileges and can be exploited by getting a victim to visit a crafted URL. The impact is high as it allows arbitrary JavaScript execution in victims' browsers, potentially exposing sensitive data or enabling account takeover through session theft. Affected versions
0.4.1
0.4.2
0.4.3
0.4.4
0.4.4.post1
0.4.4.post2
0.4.5
0.4.6
0.4.6.post1
0.4.6.post2
0.4.7
0.4.8
+ 76 more Show less
0.5.0
0.5.1
0.6.0
0.6.1
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.4.post0
0.7.4.post1
0.7.5.post1
0.7.5.post2
0.8.0
0.8.0.post0
0.8.1
0.8.1.post0
0.8.2
0.8.2.post0
0.9.0
0.9.0.post2
0.9.0.post3
0.9.0.post4
0.9.0.post5
0.9.1
0.9.1.post0
0.9.1.post1
0.9.1.post2
1.0.0
1.0.0.post0
1.0.0.post1
1.0.0.post2
1.0.0.post3
1.0.1
1.0.2
1.0.2.post0
1.1.0
1.1.0rc0
1.1.1
1.10.0
1.10.0.post0
1.10.1
1.11.0
1.12.0
1.12.0.post0
1.12.1
1.13.0
1.13.1
1.14.0
1.14.0.post0
1.15.0
1.2
1.3
1.3.post0
1.3.post1
1.4
1.4.1
1.4.1.post0
1.4.1.post1
1.5.0
1.5.0.post0
1.6.0
1.7.0
1.7.1
1.7.2
1.7.3
1.8.0
1.8.1
1.8.2
1.8.2.post0
1.8.2.post1
1.9.0
1.9.1
1.9.1.post0
1.9.2
1.9.2.post0
Fixed in
1.16.0
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-47783
GHSA-8jhr-wpcm-hh4h
PYSEC-2025-124
May 15, 2025
label-studio vulnerable to Cross-Site Scripting (Reflected) via the label_config parameter.
High
Network
Low
None
SummaryThe vulnerability allows an attacker to inject a malicious script into the context of a web page, which can lead to data theft, unauthorized actions on behalf of the user, and other attacks. DetailsThe vulnerability is reproducible when sending a properly formatted request to the
The vulnerability is specifically located in line 57, where HttpResponse is used.
PoCSend the following request after changing the
Or you can create a vulnerable HTML page by changing
Impact
Affected versions
0.4.1
0.4.2
0.4.3
0.4.4
0.4.4.post1
0.4.4.post2
0.4.5
0.4.6
0.4.6.post1
0.4.6.post2
0.4.7
0.4.8
+ 78 more Show less
0.5.0
0.5.1
0.6.0
0.6.1
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.4.post0
0.7.4.post1
0.7.5.post1
0.7.5.post2
0.8.0
0.8.0.post0
0.8.1
0.8.1.post0
0.8.2
0.8.2.post0
0.9.0
0.9.0.post2
0.9.0.post3
0.9.0.post4
0.9.0.post5
0.9.1
0.9.1.post0
0.9.1.post1
0.9.1.post2
1.0.0
1.0.0.post0
1.0.0.post1
1.0.0.post2
1.0.0.post3
1.0.1
1.0.2
1.0.2.post0
1.1.0
1.1.0rc0
1.1.1
1.10.0
1.10.0.post0
1.10.1
1.11.0
1.12.0
1.12.0.post0
1.12.1
1.13.0
1.13.1
1.14.0
1.14.0.post0
1.15.0
1.16.0
1.17.0
1.2
1.3
1.3.post0
1.3.post1
1.4
1.4.1
1.4.1.post0
1.4.1.post1
1.5.0
1.5.0.post0
1.6.0
1.7.0
1.7.1
1.7.2
1.7.3
1.8.0
1.8.1
1.8.2
1.8.2.post0
1.8.2.post1
1.9.0
1.9.1
1.9.1.post0
1.9.2
1.9.2.post0
Fixed in
1.18.0
References
Updated Jun 06, 2026 · Source: OSV.dev
CVE-2024-26152
PYSEC-2024-249
GHSA-6xv9-957j-qfhg
Feb 22, 2024
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
SummaryOn all Label Studio versions prior to 1.11.0, data imported via file upload feature is not properly sanitized prior to being rendered within a DetailsNeed permission to use the "data import" function. This was reproduced on Label Studio 1.10.1. PoC
The following are the contents of the files used in the PoC
ImpactMalicious scripts can be injected into the code, and when linked with vulnerabilities such as CSRF, it can cause even greater damage. In particular, It can become a source of further attacks, especially when linked to social engineering. Affected versions
0.4.1
0.4.2
0.4.3
0.4.4
0.4.4.post1
0.4.4.post2
0.4.5
0.4.6
0.4.6.post1
0.4.6.post2
0.4.7
0.4.8
+ 113 more Show less
0.5.0
0.5.1
0.6.0
0.6.1
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.4.post0
0.7.4.post1
0.7.5.post1
0.7.5.post2
0.8.0
0.8.0.post0
0.8.1
0.8.1.post0
0.8.2
0.8.2.post0
0.9.0
0.9.0.post2
0.9.0.post3
0.9.0.post4
0.9.0.post5
0.9.1
0.9.1.post0
0.9.1.post1
0.9.1.post2
1.0.0
1.0.0.post0
1.0.0.post1
1.0.0.post2
1.0.0.post3
1.0.1
1.0.2
1.0.2.post0
1.1.0
1.1.0rc0
1.1.1
1.10.0
1.10.0.post0
1.10.1
1.2
1.3
1.3.post0
1.3.post1
1.4
1.4.1
1.4.1.post0
1.4.1.post1
1.5.0
1.5.0.post0
1.6.0
1.7.0
1.7.1
1.7.2
1.7.3
1.8.0
1.8.1
1.8.2
1.8.2.post0
1.8.2.post1
1.9.0
1.9.1
1.9.1.post0
1.9.2
1.9.2.post0
v1.4.1
v1.4.0
v1.3.0
v1.2.0
v1.1.1
v1.1.0
v1.0.2
v1.0.1
v1.0.0
v0.9.1.post1
v0.9.1.post0
v0.9.0.post5
v0.9.0.post4
v0.9.0.post3
v0.9.0
v0.8.2
v0.8.1
v0.8.0
v0.7.5.post0
v0.7.3
v0.7.2
v0.7.1
v0.7.0
v0.6.1
v0.6.0
v0.5.1
v0.4.8
v0.4.7
v0.4.6
v0.4.5
v0.4.4
v0.4.0
v0.3.0
v0.2.2
v.0.2.1-8
v.0.2.1-5
v.0.2.1-4
v.0.2.1-3
v.0.2.1-2
v.0.2.0
v.0.1.6
v.0.1.5
v.0.1.4
v.0.1.2
v.0.1.1
v.0.1.0
Fixed in
1.11.0
References
Updated Jun 10, 2026 · Source: OSV.dev
CVE-2023-47116
GHSA-p59w-9gqw-wj8r
PYSEC-2024-127
Jan 31, 2024
Label Studio SSRF on Import Bypassing `SSRF_PROTECTION_ENABLED` Protections
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
IntroductionThis write-up describes a vulnerability found in Label Studio, a popular open source data labeling tool. The vulnerability affects all versions of Label Studio prior to OverviewLabel Studio's SSRF protections that can be enabled by setting the DescriptionThe following
The
The issue here is the SSRF validation is only performed before the request is sent, and does not validate the destination IP address. Therefore, an attacker can either redirect the request or perform a DNS rebinding attack to bypass this protection. Proof of ConceptBoth the HTTP redirection and DNS rebinding methods for bypassing Label Studio's SSRF protections are explained below. HTTP RedirectionThe python
DNS Rebinding AttackDNS rebinding can bypass SSRF protections by resolving to an external IP address for the first resolution, but when the request is sent resolves to an internal IP address that is blocked. For an example, the domain ImpactSSRF vulnerabilities pose a significant risk on cloud environments, since instance credentials are managed by internal web APIs. An attacker can bypass Label Studio's SSRF protections to access internal web servers and partially compromise the confidentiality of those internal servers. Remediation Advice
Discovered
Affected versions
0.4.1
0.4.2
0.4.3
0.4.4
0.4.4.post1
0.4.4.post2
0.4.5
0.4.6
0.4.6.post1
0.4.6.post2
0.4.7
0.4.8
+ 67 more Show less
0.5.0
0.5.1
0.6.0
0.6.1
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.4.post0
0.7.4.post1
0.7.5.post1
0.7.5.post2
0.8.0
0.8.0.post0
0.8.1
0.8.1.post0
0.8.2
0.8.2.post0
0.9.0
0.9.0.post2
0.9.0.post3
0.9.0.post4
0.9.0.post5
0.9.1
0.9.1.post0
0.9.1.post1
0.9.1.post2
1.0.0
1.0.0.post0
1.0.0.post1
1.0.0.post2
1.0.0.post3
1.0.1
1.0.2
1.0.2.post0
1.1.0
1.1.0rc0
1.1.1
1.10.0
1.10.0.post0
1.10.1
1.2
1.3
1.3.post0
1.3.post1
1.4
1.4.1
1.4.1.post0
1.4.1.post1
1.5.0
1.5.0.post0
1.6.0
1.7.0
1.7.1
1.7.2
1.7.3
1.8.0
1.8.1
1.8.2
1.8.2.post0
1.8.2.post1
1.9.0
1.9.1
1.9.1.post0
1.9.2
1.9.2.post0
Fixed in
1.11.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-23633
GHSA-fq23-g58m-799r
PYSEC-2024-128
Jan 24, 2024
Cross-site Scripting Vulnerability on Data Import
4.7
/ 10
Medium
Network
Low
None
Required
Changed
Low
None
None
IntroductionThis write-up describes a vulnerability found in Label Studio, a popular open source data labeling tool. The vulnerability affects all versions of Label Studio prior to OverviewLabel Studio had a remote import feature allowed users to import data from a remote web source, that was downloaded and could be viewed on the website. This feature could had been abused to download a HTML file that executed malicious JavaScript code in the context of the Label Studio website. DescriptionThe following code snippet in Label Studio showed that is a URL passed the SSRF verification checks, the contents of the file would be downloaded using the filename in the URL.
The downloaded file path could then be retrieved by sending a request to
Since the Proof of ConceptBelow were the steps to recreate this issue:
ImpactExecuting arbitrary JavaScript could result in an attacker performing malicious actions on Label Studio users if they visit the crafted avatar image. For an example, an attacker can craft a JavaScript payload that adds a new Django Super Administrator user if a Django administrator visits the image. Remediation Advice
Discovered
Affected versions
0.4.1
0.4.2
0.4.3
0.4.4
0.4.4.post1
0.4.4.post2
0.4.5
0.4.6
0.4.6.post1
0.4.6.post2
0.4.7
0.4.8
+ 66 more Show less
0.5.0
0.5.1
0.6.0
0.6.1
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.4.post0
0.7.4.post1
0.7.5.post1
0.7.5.post2
0.8.0
0.8.0.post0
0.8.1
0.8.1.post0
0.8.2
0.8.2.post0
0.9.0
0.9.0.post2
0.9.0.post3
0.9.0.post4
0.9.0.post5
0.9.1
0.9.1.post0
0.9.1.post1
0.9.1.post2
1.0.0
1.0.0.post0
1.0.0.post1
1.0.0.post2
1.0.0.post3
1.0.1
1.0.2
1.0.2.post0
1.1.0
1.1.0rc0
1.1.1
1.10.0
1.10.0.post0
1.2
1.3
1.3.post0
1.3.post1
1.4
1.4.1
1.4.1.post0
1.4.1.post1
1.5.0
1.5.0.post0
1.6.0
1.7.0
1.7.1
1.7.2
1.7.3
1.8.0
1.8.1
1.8.2
1.8.2.post0
1.8.2.post1
1.9.0
1.9.1
1.9.1.post0
1.9.2
1.9.2.post0
Fixed in
1.10.1
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2023-47115
GHSA-q68h-xwq5-mm7x
PYSEC-2024-126
Jan 24, 2024
Cross-site Scripting Vulnerability on Avatar Upload
7.1
/ 10
High
Network
Low
None
Required
Changed
Low
Low
Low
IntroductionThis write-up describes a vulnerability found in Label Studio, a popular open source data labeling tool. The vulnerability affects all versions of Label Studio prior to OverviewLabel Studio has a cross-site scripting (XSS) vulnerability that could be exploited when an authenticated user uploads a crafted image file for their avatar that gets rendered as a HTML file on the website. DescriptionThe following code snippet in Label Studio shows that the only verification check is that the file is an image by extracting the dimensions from the file.
Label Studio serves avatar images using Django's built-in
The issue with the Django Proof of ConceptBelow are the steps to reproduce this issue and execute JavaScript code in the context of the Label Studio website.
ImpactExecuting arbitrary JavaScript could result in an attacker performing malicious actions on Label Studio users if they visit the crafted avatar image. For an example, an attacker can craft a JavaScript payload that adds a new Django Super Administrator user if a Django administrator visits the image. Remediation Advice
Discovered
Affected versions
0.4.1
0.4.2
0.4.3
0.4.4
0.4.4.post1
0.4.4.post2
0.4.5
0.4.6
0.4.6.post1
0.4.6.post2
0.4.7
0.4.8
+ 62 more Show less
0.5.0
0.5.1
0.6.0
0.6.1
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.4.post0
0.7.4.post1
0.7.5.post1
0.7.5.post2
0.8.0
0.8.0.post0
0.8.1
0.8.1.post0
0.8.2
0.8.2.post0
0.9.0
0.9.0.post2
0.9.0.post3
0.9.0.post4
0.9.0.post5
0.9.1
0.9.1.post0
0.9.1.post1
0.9.1.post2
1.0.0
1.0.0.post0
1.0.0.post1
1.0.0.post2
1.0.0.post3
1.0.1
1.0.2
1.0.2.post0
1.1.0
1.1.0rc0
1.1.1
1.2
1.3
1.3.post0
1.3.post1
1.4
1.4.1
1.4.1.post0
1.4.1.post1
1.5.0
1.5.0.post0
1.6.0
1.7.0
1.7.1
1.7.2
1.7.3
1.8.0
1.8.1
1.8.2
1.8.2.post0
1.8.2.post1
1.9.0
1.9.1
1.9.1.post0
Fixed in
1.9.2
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2023-47117
GHSA-6hjj-gq77-j4qw
PYSEC-2023-275
Nov 14, 2023
Label Studio Object Relational Mapper Leak Vulnerability in Filtering Task
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
IntroductionThis write-up describes a vulnerability found in Label Studio, a popular open source data labeling tool. The vulnerability affects all versions of Label Studio prior to OverviewIn all current versions of Label Studio, the application allows users to insecurely set filters for filtering tasks. An attacker can construct a filter chain to filter tasks based on sensitive fields for all user accounts on the platform by exploiting Django's Object Relational Mapper (ORM). Since the results of query can be manipulated by the ORM filter, an attacker can leak these sensitive fields character by character. For an example, the following filter chain will task results by the password hash of an account on Label Studio.
For consistency, this type of vulnerability will be termed as ORM Leak in the rest of this disclosure. In addition, Label Studio had a hard coded secret key that an attacker can use to forge a session token of any user by exploiting this ORM Leak vulnerability to leak account password hashes. DescriptionThe following code snippet from the
These
The
The following code snippet of the
Finally, the
Proof of ConceptBelow are the steps to exploit about how to exploit this vulnerability to leak the password hash of an account on Label Studio.
The following example GIF demonstrates exploiting this ORM Leak vulnerability to retrieve the password hash
ImpactThis vulnerability can be exploited to completely compromise the confidentiality of highly sensitive account information, such as account password hashes. For all versions Remediation Advice
Discovered
| ||
1.7.3
patch
10 CVEs
CVE-2026-22033
PYSEC-2026-1502
GHSA-2mq9-hm29-8qch
Jul 07, 2026
Label Studio is vulnerable to full account takeover by chaining Stored XSS + IDOR in User Profile via custom_hotkeys field
Critical
Network
Low
Low
None
PrologueThese vulnerabilities have been found and chained by DCODX-AI. Validation of the exploit chain has been confirmed manually. SummaryA persistent stored cross-site scripting (XSS) vulnerability exists in the custom_hotkeys functionality of the application. An authenticated attacker (or one who can trick a user/administrator into updating their custom_hotkeys) can inject JavaScript code that executes in other users’ browsers when those users load any page using the DetailsWithin
Here, user.custom_hotkeys is run through json_dumps_ensure_ascii (in In
The serializer allows
When another user loads a page using templates/base.html (for example PoC
Example request
Example response
ImpactExploitation impact:
Who is impacted:
Affected versions
0.4.1
0.4.2
0.4.3
0.4.4
0.4.4.post1
0.4.4.post2
0.4.5
0.4.6
0.4.6.post1
0.4.6.post2
0.4.7
0.4.8
+ 83 more Show less
0.5.0
0.5.1
0.6.0
0.6.1
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.4.post0
0.7.4.post1
0.7.5.post1
0.7.5.post2
0.8.0
0.8.0.post0
0.8.1
0.8.1.post0
0.8.2
0.8.2.post0
0.9.0
0.9.0.post2
0.9.0.post3
0.9.0.post4
0.9.0.post5
0.9.1
0.9.1.post0
0.9.1.post1
0.9.1.post2
1.0.0
1.0.0.post0
1.0.0.post1
1.0.0.post2
1.0.0.post3
1.0.1
1.0.2
1.0.2.post0
1.1.0
1.1.0rc0
1.1.1
1.10.0
1.10.0.post0
1.10.1
1.11.0
1.12.0
1.12.0.post0
1.12.1
1.13.0
1.13.1
1.14.0
1.14.0.post0
1.15.0
1.16.0
1.17.0
1.18.0
1.19.0
1.2
1.20.0
1.21.0
1.22.0
1.3
1.3.post0
1.3.post1
1.4
1.4.1
1.4.1.post0
1.4.1.post1
1.5.0
1.5.0.post0
1.6.0
1.7.0
1.7.1
1.7.2
1.7.3
1.8.0
1.8.1
1.8.2
1.8.2.post0
1.8.2.post1
1.9.0
1.9.1
1.9.1.post0
1.9.2
1.9.2.post0
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-25297
PYSEC-2026-1503
GHSA-m238-fmcw-wh58
Jul 07, 2026
Label Studio allows Server-Side Request Forgery in the S3 Storage Endpoint
8.6
/ 10
High
Network
Low
None
None
Changed
High
None
None
DescriptionLabel Studio's S3 storage integration feature contains a Server-Side Request Forgery (SSRF) vulnerability in its endpoint configuration. When creating an S3 storage connection, the application allows users to specify a custom S3 endpoint URL via the s3_endpoint parameter. This endpoint URL is passed directly to the boto3 AWS SDK without proper validation or restrictions on the protocol or destination. The vulnerability allows an attacker to make the application send HTTP requests to arbitrary internal services by specifying them as the S3 endpoint. When the storage sync operation is triggered, the application attempts to make S3 API calls to the specified endpoint, effectively making HTTP requests to the target service and returning the response in error messages. This SSRF vulnerability enables attackers to bypass network segmentation and access internal services that should not be accessible from the external network. The vulnerability is particularly severe because error messages from failed requests contain the full response body, allowing data exfiltration from internal services. Steps to reproduce
The application will attempt to connect to the specified endpoint URL as if it were an S3 service. When the request fails due to invalid S3 API responses, the error message will contain the raw response from the internal service, allowing access to internal resources. Mitigations
ImpactThis vulnerability has high severity as it allows authenticated users to make requests to arbitrary internal services from the application server, potentially exposing sensitive internal resources and bypassing network segmentation. The inclusion of response data in error messages makes this particularly effective for data exfiltration. Affected versions
0.4.1
0.4.2
0.4.3
0.4.4
0.4.4.post1
0.4.4.post2
0.4.5
0.4.6
0.4.6.post1
0.4.6.post2
0.4.7
0.4.8
+ 76 more Show less
0.5.0
0.5.1
0.6.0
0.6.1
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.4.post0
0.7.4.post1
0.7.5.post1
0.7.5.post2
0.8.0
0.8.0.post0
0.8.1
0.8.1.post0
0.8.2
0.8.2.post0
0.9.0
0.9.0.post2
0.9.0.post3
0.9.0.post4
0.9.0.post5
0.9.1
0.9.1.post0
0.9.1.post1
0.9.1.post2
1.0.0
1.0.0.post0
1.0.0.post1
1.0.0.post2
1.0.0.post3
1.0.1
1.0.2
1.0.2.post0
1.1.0
1.1.0rc0
1.1.1
1.10.0
1.10.0.post0
1.10.1
1.11.0
1.12.0
1.12.0.post0
1.12.1
1.13.0
1.13.1
1.14.0
1.14.0.post0
1.15.0
1.2
1.3
1.3.post0
1.3.post1
1.4
1.4.1
1.4.1.post0
1.4.1.post1
1.5.0
1.5.0.post0
1.6.0
1.7.0
1.7.1
1.7.2
1.7.3
1.8.0
1.8.1
1.8.2
1.8.2.post0
1.8.2.post1
1.9.0
1.9.1
1.9.1.post0
1.9.2
1.9.2.post0
Fixed in
1.16.0
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-25296
PYSEC-2026-1504
GHSA-wpq5-3366-mqw4
Jul 07, 2026
Label Studio allows Cross-Site Scripting (XSS) via GET request to `/projects/upload-example` endpoint
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
DescriptionLabel Studio's The vulnerability exists because the upload-example endpoint renders user-provided HTML content without proper sanitization on a GET request. This allows attackers to inject and execute arbitrary JavaScript in victims' browsers by getting them to visit a maliciously crafted URL. This is considered vulnerable because it enables attackers to execute JavaScript in victims' contexts, potentially allowing theft of sensitive data, session hijacking, or other malicious actions. Steps to reproduce
When executed, the payload causes the application to render an HTML page containing an img tag that fails to load, triggering the onerror event handler which executes base64-decoded JavaScript, demonstrating successful XSS execution in the victim's browser. Mitigations
ImpactThe vulnerability requires no special privileges and can be exploited by getting a victim to visit a crafted URL. The impact is high as it allows arbitrary JavaScript execution in victims' browsers, potentially exposing sensitive data or enabling account takeover through session theft. Affected versions
0.4.1
0.4.2
0.4.3
0.4.4
0.4.4.post1
0.4.4.post2
0.4.5
0.4.6
0.4.6.post1
0.4.6.post2
0.4.7
0.4.8
+ 76 more Show less
0.5.0
0.5.1
0.6.0
0.6.1
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.4.post0
0.7.4.post1
0.7.5.post1
0.7.5.post2
0.8.0
0.8.0.post0
0.8.1
0.8.1.post0
0.8.2
0.8.2.post0
0.9.0
0.9.0.post2
0.9.0.post3
0.9.0.post4
0.9.0.post5
0.9.1
0.9.1.post0
0.9.1.post1
0.9.1.post2
1.0.0
1.0.0.post0
1.0.0.post1
1.0.0.post2
1.0.0.post3
1.0.1
1.0.2
1.0.2.post0
1.1.0
1.1.0rc0
1.1.1
1.10.0
1.10.0.post0
1.10.1
1.11.0
1.12.0
1.12.0.post0
1.12.1
1.13.0
1.13.1
1.14.0
1.14.0.post0
1.15.0
1.2
1.3
1.3.post0
1.3.post1
1.4
1.4.1
1.4.1.post0
1.4.1.post1
1.5.0
1.5.0.post0
1.6.0
1.7.0
1.7.1
1.7.2
1.7.3
1.8.0
1.8.1
1.8.2
1.8.2.post0
1.8.2.post1
1.9.0
1.9.1
1.9.1.post0
1.9.2
1.9.2.post0
Fixed in
1.16.0
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-47783
GHSA-8jhr-wpcm-hh4h
PYSEC-2025-124
May 15, 2025
label-studio vulnerable to Cross-Site Scripting (Reflected) via the label_config parameter.
High
Network
Low
None
SummaryThe vulnerability allows an attacker to inject a malicious script into the context of a web page, which can lead to data theft, unauthorized actions on behalf of the user, and other attacks. DetailsThe vulnerability is reproducible when sending a properly formatted request to the
The vulnerability is specifically located in line 57, where HttpResponse is used.
PoCSend the following request after changing the
Or you can create a vulnerable HTML page by changing
Impact
Affected versions
0.4.1
0.4.2
0.4.3
0.4.4
0.4.4.post1
0.4.4.post2
0.4.5
0.4.6
0.4.6.post1
0.4.6.post2
0.4.7
0.4.8
+ 78 more Show less
0.5.0
0.5.1
0.6.0
0.6.1
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.4.post0
0.7.4.post1
0.7.5.post1
0.7.5.post2
0.8.0
0.8.0.post0
0.8.1
0.8.1.post0
0.8.2
0.8.2.post0
0.9.0
0.9.0.post2
0.9.0.post3
0.9.0.post4
0.9.0.post5
0.9.1
0.9.1.post0
0.9.1.post1
0.9.1.post2
1.0.0
1.0.0.post0
1.0.0.post1
1.0.0.post2
1.0.0.post3
1.0.1
1.0.2
1.0.2.post0
1.1.0
1.1.0rc0
1.1.1
1.10.0
1.10.0.post0
1.10.1
1.11.0
1.12.0
1.12.0.post0
1.12.1
1.13.0
1.13.1
1.14.0
1.14.0.post0
1.15.0
1.16.0
1.17.0
1.2
1.3
1.3.post0
1.3.post1
1.4
1.4.1
1.4.1.post0
1.4.1.post1
1.5.0
1.5.0.post0
1.6.0
1.7.0
1.7.1
1.7.2
1.7.3
1.8.0
1.8.1
1.8.2
1.8.2.post0
1.8.2.post1
1.9.0
1.9.1
1.9.1.post0
1.9.2
1.9.2.post0
Fixed in
1.18.0
References
Updated Jun 06, 2026 · Source: OSV.dev
CVE-2024-26152
PYSEC-2024-249
GHSA-6xv9-957j-qfhg
Feb 22, 2024
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
SummaryOn all Label Studio versions prior to 1.11.0, data imported via file upload feature is not properly sanitized prior to being rendered within a DetailsNeed permission to use the "data import" function. This was reproduced on Label Studio 1.10.1. PoC
The following are the contents of the files used in the PoC
ImpactMalicious scripts can be injected into the code, and when linked with vulnerabilities such as CSRF, it can cause even greater damage. In particular, It can become a source of further attacks, especially when linked to social engineering. Affected versions
0.4.1
0.4.2
0.4.3
0.4.4
0.4.4.post1
0.4.4.post2
0.4.5
0.4.6
0.4.6.post1
0.4.6.post2
0.4.7
0.4.8
+ 113 more Show less
0.5.0
0.5.1
0.6.0
0.6.1
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.4.post0
0.7.4.post1
0.7.5.post1
0.7.5.post2
0.8.0
0.8.0.post0
0.8.1
0.8.1.post0
0.8.2
0.8.2.post0
0.9.0
0.9.0.post2
0.9.0.post3
0.9.0.post4
0.9.0.post5
0.9.1
0.9.1.post0
0.9.1.post1
0.9.1.post2
1.0.0
1.0.0.post0
1.0.0.post1
1.0.0.post2
1.0.0.post3
1.0.1
1.0.2
1.0.2.post0
1.1.0
1.1.0rc0
1.1.1
1.10.0
1.10.0.post0
1.10.1
1.2
1.3
1.3.post0
1.3.post1
1.4
1.4.1
1.4.1.post0
1.4.1.post1
1.5.0
1.5.0.post0
1.6.0
1.7.0
1.7.1
1.7.2
1.7.3
1.8.0
1.8.1
1.8.2
1.8.2.post0
1.8.2.post1
1.9.0
1.9.1
1.9.1.post0
1.9.2
1.9.2.post0
v1.4.1
v1.4.0
v1.3.0
v1.2.0
v1.1.1
v1.1.0
v1.0.2
v1.0.1
v1.0.0
v0.9.1.post1
v0.9.1.post0
v0.9.0.post5
v0.9.0.post4
v0.9.0.post3
v0.9.0
v0.8.2
v0.8.1
v0.8.0
v0.7.5.post0
v0.7.3
v0.7.2
v0.7.1
v0.7.0
v0.6.1
v0.6.0
v0.5.1
v0.4.8
v0.4.7
v0.4.6
v0.4.5
v0.4.4
v0.4.0
v0.3.0
v0.2.2
v.0.2.1-8
v.0.2.1-5
v.0.2.1-4
v.0.2.1-3
v.0.2.1-2
v.0.2.0
v.0.1.6
v.0.1.5
v.0.1.4
v.0.1.2
v.0.1.1
v.0.1.0
Fixed in
1.11.0
References
Updated Jun 10, 2026 · Source: OSV.dev
CVE-2023-47116
GHSA-p59w-9gqw-wj8r
PYSEC-2024-127
Jan 31, 2024
Label Studio SSRF on Import Bypassing `SSRF_PROTECTION_ENABLED` Protections
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
IntroductionThis write-up describes a vulnerability found in Label Studio, a popular open source data labeling tool. The vulnerability affects all versions of Label Studio prior to OverviewLabel Studio's SSRF protections that can be enabled by setting the DescriptionThe following
The
The issue here is the SSRF validation is only performed before the request is sent, and does not validate the destination IP address. Therefore, an attacker can either redirect the request or perform a DNS rebinding attack to bypass this protection. Proof of ConceptBoth the HTTP redirection and DNS rebinding methods for bypassing Label Studio's SSRF protections are explained below. HTTP RedirectionThe python
DNS Rebinding AttackDNS rebinding can bypass SSRF protections by resolving to an external IP address for the first resolution, but when the request is sent resolves to an internal IP address that is blocked. For an example, the domain ImpactSSRF vulnerabilities pose a significant risk on cloud environments, since instance credentials are managed by internal web APIs. An attacker can bypass Label Studio's SSRF protections to access internal web servers and partially compromise the confidentiality of those internal servers. Remediation Advice
Discovered
Affected versions
0.4.1
0.4.2
0.4.3
0.4.4
0.4.4.post1
0.4.4.post2
0.4.5
0.4.6
0.4.6.post1
0.4.6.post2
0.4.7
0.4.8
+ 67 more Show less
0.5.0
0.5.1
0.6.0
0.6.1
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.4.post0
0.7.4.post1
0.7.5.post1
0.7.5.post2
0.8.0
0.8.0.post0
0.8.1
0.8.1.post0
0.8.2
0.8.2.post0
0.9.0
0.9.0.post2
0.9.0.post3
0.9.0.post4
0.9.0.post5
0.9.1
0.9.1.post0
0.9.1.post1
0.9.1.post2
1.0.0
1.0.0.post0
1.0.0.post1
1.0.0.post2
1.0.0.post3
1.0.1
1.0.2
1.0.2.post0
1.1.0
1.1.0rc0
1.1.1
1.10.0
1.10.0.post0
1.10.1
1.2
1.3
1.3.post0
1.3.post1
1.4
1.4.1
1.4.1.post0
1.4.1.post1
1.5.0
1.5.0.post0
1.6.0
1.7.0
1.7.1
1.7.2
1.7.3
1.8.0
1.8.1
1.8.2
1.8.2.post0
1.8.2.post1
1.9.0
1.9.1
1.9.1.post0
1.9.2
1.9.2.post0
Fixed in
1.11.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-23633
GHSA-fq23-g58m-799r
PYSEC-2024-128
Jan 24, 2024
Cross-site Scripting Vulnerability on Data Import
4.7
/ 10
Medium
Network
Low
None
Required
Changed
Low
None
None
IntroductionThis write-up describes a vulnerability found in Label Studio, a popular open source data labeling tool. The vulnerability affects all versions of Label Studio prior to OverviewLabel Studio had a remote import feature allowed users to import data from a remote web source, that was downloaded and could be viewed on the website. This feature could had been abused to download a HTML file that executed malicious JavaScript code in the context of the Label Studio website. DescriptionThe following code snippet in Label Studio showed that is a URL passed the SSRF verification checks, the contents of the file would be downloaded using the filename in the URL.
The downloaded file path could then be retrieved by sending a request to
Since the Proof of ConceptBelow were the steps to recreate this issue:
ImpactExecuting arbitrary JavaScript could result in an attacker performing malicious actions on Label Studio users if they visit the crafted avatar image. For an example, an attacker can craft a JavaScript payload that adds a new Django Super Administrator user if a Django administrator visits the image. Remediation Advice
Discovered
Affected versions
0.4.1
0.4.2
0.4.3
0.4.4
0.4.4.post1
0.4.4.post2
0.4.5
0.4.6
0.4.6.post1
0.4.6.post2
0.4.7
0.4.8
+ 66 more Show less
0.5.0
0.5.1
0.6.0
0.6.1
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.4.post0
0.7.4.post1
0.7.5.post1
0.7.5.post2
0.8.0
0.8.0.post0
0.8.1
0.8.1.post0
0.8.2
0.8.2.post0
0.9.0
0.9.0.post2
0.9.0.post3
0.9.0.post4
0.9.0.post5
0.9.1
0.9.1.post0
0.9.1.post1
0.9.1.post2
1.0.0
1.0.0.post0
1.0.0.post1
1.0.0.post2
1.0.0.post3
1.0.1
1.0.2
1.0.2.post0
1.1.0
1.1.0rc0
1.1.1
1.10.0
1.10.0.post0
1.2
1.3
1.3.post0
1.3.post1
1.4
1.4.1
1.4.1.post0
1.4.1.post1
1.5.0
1.5.0.post0
1.6.0
1.7.0
1.7.1
1.7.2
1.7.3
1.8.0
1.8.1
1.8.2
1.8.2.post0
1.8.2.post1
1.9.0
1.9.1
1.9.1.post0
1.9.2
1.9.2.post0
Fixed in
1.10.1
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2023-47115
GHSA-q68h-xwq5-mm7x
PYSEC-2024-126
Jan 24, 2024
Cross-site Scripting Vulnerability on Avatar Upload
7.1
/ 10
High
Network
Low
None
Required
Changed
Low
Low
Low
IntroductionThis write-up describes a vulnerability found in Label Studio, a popular open source data labeling tool. The vulnerability affects all versions of Label Studio prior to OverviewLabel Studio has a cross-site scripting (XSS) vulnerability that could be exploited when an authenticated user uploads a crafted image file for their avatar that gets rendered as a HTML file on the website. DescriptionThe following code snippet in Label Studio shows that the only verification check is that the file is an image by extracting the dimensions from the file.
Label Studio serves avatar images using Django's built-in
The issue with the Django Proof of ConceptBelow are the steps to reproduce this issue and execute JavaScript code in the context of the Label Studio website.
ImpactExecuting arbitrary JavaScript could result in an attacker performing malicious actions on Label Studio users if they visit the crafted avatar image. For an example, an attacker can craft a JavaScript payload that adds a new Django Super Administrator user if a Django administrator visits the image. Remediation Advice
Discovered
Affected versions
0.4.1
0.4.2
0.4.3
0.4.4
0.4.4.post1
0.4.4.post2
0.4.5
0.4.6
0.4.6.post1
0.4.6.post2
0.4.7
0.4.8
+ 62 more Show less
0.5.0
0.5.1
0.6.0
0.6.1
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.4.post0
0.7.4.post1
0.7.5.post1
0.7.5.post2
0.8.0
0.8.0.post0
0.8.1
0.8.1.post0
0.8.2
0.8.2.post0
0.9.0
0.9.0.post2
0.9.0.post3
0.9.0.post4
0.9.0.post5
0.9.1
0.9.1.post0
0.9.1.post1
0.9.1.post2
1.0.0
1.0.0.post0
1.0.0.post1
1.0.0.post2
1.0.0.post3
1.0.1
1.0.2
1.0.2.post0
1.1.0
1.1.0rc0
1.1.1
1.2
1.3
1.3.post0
1.3.post1
1.4
1.4.1
1.4.1.post0
1.4.1.post1
1.5.0
1.5.0.post0
1.6.0
1.7.0
1.7.1
1.7.2
1.7.3
1.8.0
1.8.1
1.8.2
1.8.2.post0
1.8.2.post1
1.9.0
1.9.1
1.9.1.post0
Fixed in
1.9.2
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2023-47117
GHSA-6hjj-gq77-j4qw
PYSEC-2023-275
Nov 14, 2023
Label Studio Object Relational Mapper Leak Vulnerability in Filtering Task
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
IntroductionThis write-up describes a vulnerability found in Label Studio, a popular open source data labeling tool. The vulnerability affects all versions of Label Studio prior to OverviewIn all current versions of Label Studio, the application allows users to insecurely set filters for filtering tasks. An attacker can construct a filter chain to filter tasks based on sensitive fields for all user accounts on the platform by exploiting Django's Object Relational Mapper (ORM). Since the results of query can be manipulated by the ORM filter, an attacker can leak these sensitive fields character by character. For an example, the following filter chain will task results by the password hash of an account on Label Studio.
For consistency, this type of vulnerability will be termed as ORM Leak in the rest of this disclosure. In addition, Label Studio had a hard coded secret key that an attacker can use to forge a session token of any user by exploiting this ORM Leak vulnerability to leak account password hashes. DescriptionThe following code snippet from the
These
The
The following code snippet of the
Finally, the
Proof of ConceptBelow are the steps to exploit about how to exploit this vulnerability to leak the password hash of an account on Label Studio.
The following example GIF demonstrates exploiting this ORM Leak vulnerability to retrieve the password hash
ImpactThis vulnerability can be exploited to completely compromise the confidentiality of highly sensitive account information, such as account password hashes. For all versions Remediation Advice
Discovered
| ||
1.7.2
patch
10 CVEs
CVE-2026-22033
PYSEC-2026-1502
GHSA-2mq9-hm29-8qch
Jul 07, 2026
Label Studio is vulnerable to full account takeover by chaining Stored XSS + IDOR in User Profile via custom_hotkeys field
Critical
Network
Low
Low
None
PrologueThese vulnerabilities have been found and chained by DCODX-AI. Validation of the exploit chain has been confirmed manually. SummaryA persistent stored cross-site scripting (XSS) vulnerability exists in the custom_hotkeys functionality of the application. An authenticated attacker (or one who can trick a user/administrator into updating their custom_hotkeys) can inject JavaScript code that executes in other users’ browsers when those users load any page using the DetailsWithin
Here, user.custom_hotkeys is run through json_dumps_ensure_ascii (in In
The serializer allows
When another user loads a page using templates/base.html (for example PoC
Example request
Example response
ImpactExploitation impact:
Who is impacted:
Affected versions
0.4.1
0.4.2
0.4.3
0.4.4
0.4.4.post1
0.4.4.post2
0.4.5
0.4.6
0.4.6.post1
0.4.6.post2
0.4.7
0.4.8
+ 83 more Show less
0.5.0
0.5.1
0.6.0
0.6.1
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.4.post0
0.7.4.post1
0.7.5.post1
0.7.5.post2
0.8.0
0.8.0.post0
0.8.1
0.8.1.post0
0.8.2
0.8.2.post0
0.9.0
0.9.0.post2
0.9.0.post3
0.9.0.post4
0.9.0.post5
0.9.1
0.9.1.post0
0.9.1.post1
0.9.1.post2
1.0.0
1.0.0.post0
1.0.0.post1
1.0.0.post2
1.0.0.post3
1.0.1
1.0.2
1.0.2.post0
1.1.0
1.1.0rc0
1.1.1
1.10.0
1.10.0.post0
1.10.1
1.11.0
1.12.0
1.12.0.post0
1.12.1
1.13.0
1.13.1
1.14.0
1.14.0.post0
1.15.0
1.16.0
1.17.0
1.18.0
1.19.0
1.2
1.20.0
1.21.0
1.22.0
1.3
1.3.post0
1.3.post1
1.4
1.4.1
1.4.1.post0
1.4.1.post1
1.5.0
1.5.0.post0
1.6.0
1.7.0
1.7.1
1.7.2
1.7.3
1.8.0
1.8.1
1.8.2
1.8.2.post0
1.8.2.post1
1.9.0
1.9.1
1.9.1.post0
1.9.2
1.9.2.post0
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-25297
PYSEC-2026-1503
GHSA-m238-fmcw-wh58
Jul 07, 2026
Label Studio allows Server-Side Request Forgery in the S3 Storage Endpoint
8.6
/ 10
High
Network
Low
None
None
Changed
High
None
None
DescriptionLabel Studio's S3 storage integration feature contains a Server-Side Request Forgery (SSRF) vulnerability in its endpoint configuration. When creating an S3 storage connection, the application allows users to specify a custom S3 endpoint URL via the s3_endpoint parameter. This endpoint URL is passed directly to the boto3 AWS SDK without proper validation or restrictions on the protocol or destination. The vulnerability allows an attacker to make the application send HTTP requests to arbitrary internal services by specifying them as the S3 endpoint. When the storage sync operation is triggered, the application attempts to make S3 API calls to the specified endpoint, effectively making HTTP requests to the target service and returning the response in error messages. This SSRF vulnerability enables attackers to bypass network segmentation and access internal services that should not be accessible from the external network. The vulnerability is particularly severe because error messages from failed requests contain the full response body, allowing data exfiltration from internal services. Steps to reproduce
The application will attempt to connect to the specified endpoint URL as if it were an S3 service. When the request fails due to invalid S3 API responses, the error message will contain the raw response from the internal service, allowing access to internal resources. Mitigations
ImpactThis vulnerability has high severity as it allows authenticated users to make requests to arbitrary internal services from the application server, potentially exposing sensitive internal resources and bypassing network segmentation. The inclusion of response data in error messages makes this particularly effective for data exfiltration. Affected versions
0.4.1
0.4.2
0.4.3
0.4.4
0.4.4.post1
0.4.4.post2
0.4.5
0.4.6
0.4.6.post1
0.4.6.post2
0.4.7
0.4.8
+ 76 more Show less
0.5.0
0.5.1
0.6.0
0.6.1
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.4.post0
0.7.4.post1
0.7.5.post1
0.7.5.post2
0.8.0
0.8.0.post0
0.8.1
0.8.1.post0
0.8.2
0.8.2.post0
0.9.0
0.9.0.post2
0.9.0.post3
0.9.0.post4
0.9.0.post5
0.9.1
0.9.1.post0
0.9.1.post1
0.9.1.post2
1.0.0
1.0.0.post0
1.0.0.post1
1.0.0.post2
1.0.0.post3
1.0.1
1.0.2
1.0.2.post0
1.1.0
1.1.0rc0
1.1.1
1.10.0
1.10.0.post0
1.10.1
1.11.0
1.12.0
1.12.0.post0
1.12.1
1.13.0
1.13.1
1.14.0
1.14.0.post0
1.15.0
1.2
1.3
1.3.post0
1.3.post1
1.4
1.4.1
1.4.1.post0
1.4.1.post1
1.5.0
1.5.0.post0
1.6.0
1.7.0
1.7.1
1.7.2
1.7.3
1.8.0
1.8.1
1.8.2
1.8.2.post0
1.8.2.post1
1.9.0
1.9.1
1.9.1.post0
1.9.2
1.9.2.post0
Fixed in
1.16.0
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-25296
PYSEC-2026-1504
GHSA-wpq5-3366-mqw4
Jul 07, 2026
Label Studio allows Cross-Site Scripting (XSS) via GET request to `/projects/upload-example` endpoint
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
DescriptionLabel Studio's The vulnerability exists because the upload-example endpoint renders user-provided HTML content without proper sanitization on a GET request. This allows attackers to inject and execute arbitrary JavaScript in victims' browsers by getting them to visit a maliciously crafted URL. This is considered vulnerable because it enables attackers to execute JavaScript in victims' contexts, potentially allowing theft of sensitive data, session hijacking, or other malicious actions. Steps to reproduce
When executed, the payload causes the application to render an HTML page containing an img tag that fails to load, triggering the onerror event handler which executes base64-decoded JavaScript, demonstrating successful XSS execution in the victim's browser. Mitigations
ImpactThe vulnerability requires no special privileges and can be exploited by getting a victim to visit a crafted URL. The impact is high as it allows arbitrary JavaScript execution in victims' browsers, potentially exposing sensitive data or enabling account takeover through session theft. Affected versions
0.4.1
0.4.2
0.4.3
0.4.4
0.4.4.post1
0.4.4.post2
0.4.5
0.4.6
0.4.6.post1
0.4.6.post2
0.4.7
0.4.8
+ 76 more Show less
0.5.0
0.5.1
0.6.0
0.6.1
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.4.post0
0.7.4.post1
0.7.5.post1
0.7.5.post2
0.8.0
0.8.0.post0
0.8.1
0.8.1.post0
0.8.2
0.8.2.post0
0.9.0
0.9.0.post2
0.9.0.post3
0.9.0.post4
0.9.0.post5
0.9.1
0.9.1.post0
0.9.1.post1
0.9.1.post2
1.0.0
1.0.0.post0
1.0.0.post1
1.0.0.post2
1.0.0.post3
1.0.1
1.0.2
1.0.2.post0
1.1.0
1.1.0rc0
1.1.1
1.10.0
1.10.0.post0
1.10.1
1.11.0
1.12.0
1.12.0.post0
1.12.1
1.13.0
1.13.1
1.14.0
1.14.0.post0
1.15.0
1.2
1.3
1.3.post0
1.3.post1
1.4
1.4.1
1.4.1.post0
1.4.1.post1
1.5.0
1.5.0.post0
1.6.0
1.7.0
1.7.1
1.7.2
1.7.3
1.8.0
1.8.1
1.8.2
1.8.2.post0
1.8.2.post1
1.9.0
1.9.1
1.9.1.post0
1.9.2
1.9.2.post0
Fixed in
1.16.0
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-47783
GHSA-8jhr-wpcm-hh4h
PYSEC-2025-124
May 15, 2025
label-studio vulnerable to Cross-Site Scripting (Reflected) via the label_config parameter.
High
Network
Low
None
SummaryThe vulnerability allows an attacker to inject a malicious script into the context of a web page, which can lead to data theft, unauthorized actions on behalf of the user, and other attacks. DetailsThe vulnerability is reproducible when sending a properly formatted request to the
The vulnerability is specifically located in line 57, where HttpResponse is used.
PoCSend the following request after changing the
Or you can create a vulnerable HTML page by changing
Impact
Affected versions
0.4.1
0.4.2
0.4.3
0.4.4
0.4.4.post1
0.4.4.post2
0.4.5
0.4.6
0.4.6.post1
0.4.6.post2
0.4.7
0.4.8
+ 78 more Show less
0.5.0
0.5.1
0.6.0
0.6.1
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.4.post0
0.7.4.post1
0.7.5.post1
0.7.5.post2
0.8.0
0.8.0.post0
0.8.1
0.8.1.post0
0.8.2
0.8.2.post0
0.9.0
0.9.0.post2
0.9.0.post3
0.9.0.post4
0.9.0.post5
0.9.1
0.9.1.post0
0.9.1.post1
0.9.1.post2
1.0.0
1.0.0.post0
1.0.0.post1
1.0.0.post2
1.0.0.post3
1.0.1
1.0.2
1.0.2.post0
1.1.0
1.1.0rc0
1.1.1
1.10.0
1.10.0.post0
1.10.1
1.11.0
1.12.0
1.12.0.post0
1.12.1
1.13.0
1.13.1
1.14.0
1.14.0.post0
1.15.0
1.16.0
1.17.0
1.2
1.3
1.3.post0
1.3.post1
1.4
1.4.1
1.4.1.post0
1.4.1.post1
1.5.0
1.5.0.post0
1.6.0
1.7.0
1.7.1
1.7.2
1.7.3
1.8.0
1.8.1
1.8.2
1.8.2.post0
1.8.2.post1
1.9.0
1.9.1
1.9.1.post0
1.9.2
1.9.2.post0
Fixed in
1.18.0
References
Updated Jun 06, 2026 · Source: OSV.dev
CVE-2024-26152
PYSEC-2024-249
GHSA-6xv9-957j-qfhg
Feb 22, 2024
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
SummaryOn all Label Studio versions prior to 1.11.0, data imported via file upload feature is not properly sanitized prior to being rendered within a DetailsNeed permission to use the "data import" function. This was reproduced on Label Studio 1.10.1. PoC
The following are the contents of the files used in the PoC
ImpactMalicious scripts can be injected into the code, and when linked with vulnerabilities such as CSRF, it can cause even greater damage. In particular, It can become a source of further attacks, especially when linked to social engineering. Affected versions
0.4.1
0.4.2
0.4.3
0.4.4
0.4.4.post1
0.4.4.post2
0.4.5
0.4.6
0.4.6.post1
0.4.6.post2
0.4.7
0.4.8
+ 113 more Show less
0.5.0
0.5.1
0.6.0
0.6.1
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.4.post0
0.7.4.post1
0.7.5.post1
0.7.5.post2
0.8.0
0.8.0.post0
0.8.1
0.8.1.post0
0.8.2
0.8.2.post0
0.9.0
0.9.0.post2
0.9.0.post3
0.9.0.post4
0.9.0.post5
0.9.1
0.9.1.post0
0.9.1.post1
0.9.1.post2
1.0.0
1.0.0.post0
1.0.0.post1
1.0.0.post2
1.0.0.post3
1.0.1
1.0.2
1.0.2.post0
1.1.0
1.1.0rc0
1.1.1
1.10.0
1.10.0.post0
1.10.1
1.2
1.3
1.3.post0
1.3.post1
1.4
1.4.1
1.4.1.post0
1.4.1.post1
1.5.0
1.5.0.post0
1.6.0
1.7.0
1.7.1
1.7.2
1.7.3
1.8.0
1.8.1
1.8.2
1.8.2.post0
1.8.2.post1
1.9.0
1.9.1
1.9.1.post0
1.9.2
1.9.2.post0
v1.4.1
v1.4.0
v1.3.0
v1.2.0
v1.1.1
v1.1.0
v1.0.2
v1.0.1
v1.0.0
v0.9.1.post1
v0.9.1.post0
v0.9.0.post5
v0.9.0.post4
v0.9.0.post3
v0.9.0
v0.8.2
v0.8.1
v0.8.0
v0.7.5.post0
v0.7.3
v0.7.2
v0.7.1
v0.7.0
v0.6.1
v0.6.0
v0.5.1
v0.4.8
v0.4.7
v0.4.6
v0.4.5
v0.4.4
v0.4.0
v0.3.0
v0.2.2
v.0.2.1-8
v.0.2.1-5
v.0.2.1-4
v.0.2.1-3
v.0.2.1-2
v.0.2.0
v.0.1.6
v.0.1.5
v.0.1.4
v.0.1.2
v.0.1.1
v.0.1.0
Fixed in
1.11.0
References
Updated Jun 10, 2026 · Source: OSV.dev
CVE-2023-47116
GHSA-p59w-9gqw-wj8r
PYSEC-2024-127
Jan 31, 2024
Label Studio SSRF on Import Bypassing `SSRF_PROTECTION_ENABLED` Protections
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
IntroductionThis write-up describes a vulnerability found in Label Studio, a popular open source data labeling tool. The vulnerability affects all versions of Label Studio prior to OverviewLabel Studio's SSRF protections that can be enabled by setting the DescriptionThe following
The
The issue here is the SSRF validation is only performed before the request is sent, and does not validate the destination IP address. Therefore, an attacker can either redirect the request or perform a DNS rebinding attack to bypass this protection. Proof of ConceptBoth the HTTP redirection and DNS rebinding methods for bypassing Label Studio's SSRF protections are explained below. HTTP RedirectionThe python
DNS Rebinding AttackDNS rebinding can bypass SSRF protections by resolving to an external IP address for the first resolution, but when the request is sent resolves to an internal IP address that is blocked. For an example, the domain ImpactSSRF vulnerabilities pose a significant risk on cloud environments, since instance credentials are managed by internal web APIs. An attacker can bypass Label Studio's SSRF protections to access internal web servers and partially compromise the confidentiality of those internal servers. Remediation Advice
Discovered
Affected versions
0.4.1
0.4.2
0.4.3
0.4.4
0.4.4.post1
0.4.4.post2
0.4.5
0.4.6
0.4.6.post1
0.4.6.post2
0.4.7
0.4.8
+ 67 more Show less
0.5.0
0.5.1
0.6.0
0.6.1
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.4.post0
0.7.4.post1
0.7.5.post1
0.7.5.post2
0.8.0
0.8.0.post0
0.8.1
0.8.1.post0
0.8.2
0.8.2.post0
0.9.0
0.9.0.post2
0.9.0.post3
0.9.0.post4
0.9.0.post5
0.9.1
0.9.1.post0
0.9.1.post1
0.9.1.post2
1.0.0
1.0.0.post0
1.0.0.post1
1.0.0.post2
1.0.0.post3
1.0.1
1.0.2
1.0.2.post0
1.1.0
1.1.0rc0
1.1.1
1.10.0
1.10.0.post0
1.10.1
1.2
1.3
1.3.post0
1.3.post1
1.4
1.4.1
1.4.1.post0
1.4.1.post1
1.5.0
1.5.0.post0
1.6.0
1.7.0
1.7.1
1.7.2
1.7.3
1.8.0
1.8.1
1.8.2
1.8.2.post0
1.8.2.post1
1.9.0
1.9.1
1.9.1.post0
1.9.2
1.9.2.post0
Fixed in
1.11.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-23633
GHSA-fq23-g58m-799r
PYSEC-2024-128
Jan 24, 2024
Cross-site Scripting Vulnerability on Data Import
4.7
/ 10
Medium
Network
Low
None
Required
Changed
Low
None
None
IntroductionThis write-up describes a vulnerability found in Label Studio, a popular open source data labeling tool. The vulnerability affects all versions of Label Studio prior to OverviewLabel Studio had a remote import feature allowed users to import data from a remote web source, that was downloaded and could be viewed on the website. This feature could had been abused to download a HTML file that executed malicious JavaScript code in the context of the Label Studio website. DescriptionThe following code snippet in Label Studio showed that is a URL passed the SSRF verification checks, the contents of the file would be downloaded using the filename in the URL.
The downloaded file path could then be retrieved by sending a request to
Since the Proof of ConceptBelow were the steps to recreate this issue:
ImpactExecuting arbitrary JavaScript could result in an attacker performing malicious actions on Label Studio users if they visit the crafted avatar image. For an example, an attacker can craft a JavaScript payload that adds a new Django Super Administrator user if a Django administrator visits the image. Remediation Advice
Discovered
Affected versions
0.4.1
0.4.2
0.4.3
0.4.4
0.4.4.post1
0.4.4.post2
0.4.5
0.4.6
0.4.6.post1
0.4.6.post2
0.4.7
0.4.8
+ 66 more Show less
0.5.0
0.5.1
0.6.0
0.6.1
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.4.post0
0.7.4.post1
0.7.5.post1
0.7.5.post2
0.8.0
0.8.0.post0
0.8.1
0.8.1.post0
0.8.2
0.8.2.post0
0.9.0
0.9.0.post2
0.9.0.post3
0.9.0.post4
0.9.0.post5
0.9.1
0.9.1.post0
0.9.1.post1
0.9.1.post2
1.0.0
1.0.0.post0
1.0.0.post1
1.0.0.post2
1.0.0.post3
1.0.1
1.0.2
1.0.2.post0
1.1.0
1.1.0rc0
1.1.1
1.10.0
1.10.0.post0
1.2
1.3
1.3.post0
1.3.post1
1.4
1.4.1
1.4.1.post0
1.4.1.post1
1.5.0
1.5.0.post0
1.6.0
1.7.0
1.7.1
1.7.2
1.7.3
1.8.0
1.8.1
1.8.2
1.8.2.post0
1.8.2.post1
1.9.0
1.9.1
1.9.1.post0
1.9.2
1.9.2.post0
Fixed in
1.10.1
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2023-47115
GHSA-q68h-xwq5-mm7x
PYSEC-2024-126
Jan 24, 2024
Cross-site Scripting Vulnerability on Avatar Upload
7.1
/ 10
High
Network
Low
None
Required
Changed
Low
Low
Low
IntroductionThis write-up describes a vulnerability found in Label Studio, a popular open source data labeling tool. The vulnerability affects all versions of Label Studio prior to OverviewLabel Studio has a cross-site scripting (XSS) vulnerability that could be exploited when an authenticated user uploads a crafted image file for their avatar that gets rendered as a HTML file on the website. DescriptionThe following code snippet in Label Studio shows that the only verification check is that the file is an image by extracting the dimensions from the file.
Label Studio serves avatar images using Django's built-in
The issue with the Django Proof of ConceptBelow are the steps to reproduce this issue and execute JavaScript code in the context of the Label Studio website.
ImpactExecuting arbitrary JavaScript could result in an attacker performing malicious actions on Label Studio users if they visit the crafted avatar image. For an example, an attacker can craft a JavaScript payload that adds a new Django Super Administrator user if a Django administrator visits the image. Remediation Advice
Discovered
Affected versions
0.4.1
0.4.2
0.4.3
0.4.4
0.4.4.post1
0.4.4.post2
0.4.5
0.4.6
0.4.6.post1
0.4.6.post2
0.4.7
0.4.8
+ 62 more Show less
0.5.0
0.5.1
0.6.0
0.6.1
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.4.post0
0.7.4.post1
0.7.5.post1
0.7.5.post2
0.8.0
0.8.0.post0
0.8.1
0.8.1.post0
0.8.2
0.8.2.post0
0.9.0
0.9.0.post2
0.9.0.post3
0.9.0.post4
0.9.0.post5
0.9.1
0.9.1.post0
0.9.1.post1
0.9.1.post2
1.0.0
1.0.0.post0
1.0.0.post1
1.0.0.post2
1.0.0.post3
1.0.1
1.0.2
1.0.2.post0
1.1.0
1.1.0rc0
1.1.1
1.2
1.3
1.3.post0
1.3.post1
1.4
1.4.1
1.4.1.post0
1.4.1.post1
1.5.0
1.5.0.post0
1.6.0
1.7.0
1.7.1
1.7.2
1.7.3
1.8.0
1.8.1
1.8.2
1.8.2.post0
1.8.2.post1
1.9.0
1.9.1
1.9.1.post0
Fixed in
1.9.2
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2023-47117
GHSA-6hjj-gq77-j4qw
PYSEC-2023-275
Nov 14, 2023
Label Studio Object Relational Mapper Leak Vulnerability in Filtering Task
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
IntroductionThis write-up describes a vulnerability found in Label Studio, a popular open source data labeling tool. The vulnerability affects all versions of Label Studio prior to OverviewIn all current versions of Label Studio, the application allows users to insecurely set filters for filtering tasks. An attacker can construct a filter chain to filter tasks based on sensitive fields for all user accounts on the platform by exploiting Django's Object Relational Mapper (ORM). Since the results of query can be manipulated by the ORM filter, an attacker can leak these sensitive fields character by character. For an example, the following filter chain will task results by the password hash of an account on Label Studio.
For consistency, this type of vulnerability will be termed as ORM Leak in the rest of this disclosure. In addition, Label Studio had a hard coded secret key that an attacker can use to forge a session token of any user by exploiting this ORM Leak vulnerability to leak account password hashes. DescriptionThe following code snippet from the
These
The
The following code snippet of the
Finally, the
Proof of ConceptBelow are the steps to exploit about how to exploit this vulnerability to leak the password hash of an account on Label Studio.
The following example GIF demonstrates exploiting this ORM Leak vulnerability to retrieve the password hash
ImpactThis vulnerability can be exploited to completely compromise the confidentiality of highly sensitive account information, such as account password hashes. For all versions Remediation Advice
Discovered
| ||
1.7.1
patch
11 CVEs
CVE-2026-22033
PYSEC-2026-1502
GHSA-2mq9-hm29-8qch
Jul 07, 2026
Label Studio is vulnerable to full account takeover by chaining Stored XSS + IDOR in User Profile via custom_hotkeys field
Critical
Network
Low
Low
None
PrologueThese vulnerabilities have been found and chained by DCODX-AI. Validation of the exploit chain has been confirmed manually. SummaryA persistent stored cross-site scripting (XSS) vulnerability exists in the custom_hotkeys functionality of the application. An authenticated attacker (or one who can trick a user/administrator into updating their custom_hotkeys) can inject JavaScript code that executes in other users’ browsers when those users load any page using the DetailsWithin
Here, user.custom_hotkeys is run through json_dumps_ensure_ascii (in In
The serializer allows
When another user loads a page using templates/base.html (for example PoC
Example request
Example response
ImpactExploitation impact:
Who is impacted:
Affected versions
0.4.1
0.4.2
0.4.3
0.4.4
0.4.4.post1
0.4.4.post2
0.4.5
0.4.6
0.4.6.post1
0.4.6.post2
0.4.7
0.4.8
+ 83 more Show less
0.5.0
0.5.1
0.6.0
0.6.1
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.4.post0
0.7.4.post1
0.7.5.post1
0.7.5.post2
0.8.0
0.8.0.post0
0.8.1
0.8.1.post0
0.8.2
0.8.2.post0
0.9.0
0.9.0.post2
0.9.0.post3
0.9.0.post4
0.9.0.post5
0.9.1
0.9.1.post0
0.9.1.post1
0.9.1.post2
1.0.0
1.0.0.post0
1.0.0.post1
1.0.0.post2
1.0.0.post3
1.0.1
1.0.2
1.0.2.post0
1.1.0
1.1.0rc0
1.1.1
1.10.0
1.10.0.post0
1.10.1
1.11.0
1.12.0
1.12.0.post0
1.12.1
1.13.0
1.13.1
1.14.0
1.14.0.post0
1.15.0
1.16.0
1.17.0
1.18.0
1.19.0
1.2
1.20.0
1.21.0
1.22.0
1.3
1.3.post0
1.3.post1
1.4
1.4.1
1.4.1.post0
1.4.1.post1
1.5.0
1.5.0.post0
1.6.0
1.7.0
1.7.1
1.7.2
1.7.3
1.8.0
1.8.1
1.8.2
1.8.2.post0
1.8.2.post1
1.9.0
1.9.1
1.9.1.post0
1.9.2
1.9.2.post0
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-25297
PYSEC-2026-1503
GHSA-m238-fmcw-wh58
Jul 07, 2026
Label Studio allows Server-Side Request Forgery in the S3 Storage Endpoint
8.6
/ 10
High
Network
Low
None
None
Changed
High
None
None
DescriptionLabel Studio's S3 storage integration feature contains a Server-Side Request Forgery (SSRF) vulnerability in its endpoint configuration. When creating an S3 storage connection, the application allows users to specify a custom S3 endpoint URL via the s3_endpoint parameter. This endpoint URL is passed directly to the boto3 AWS SDK without proper validation or restrictions on the protocol or destination. The vulnerability allows an attacker to make the application send HTTP requests to arbitrary internal services by specifying them as the S3 endpoint. When the storage sync operation is triggered, the application attempts to make S3 API calls to the specified endpoint, effectively making HTTP requests to the target service and returning the response in error messages. This SSRF vulnerability enables attackers to bypass network segmentation and access internal services that should not be accessible from the external network. The vulnerability is particularly severe because error messages from failed requests contain the full response body, allowing data exfiltration from internal services. Steps to reproduce
The application will attempt to connect to the specified endpoint URL as if it were an S3 service. When the request fails due to invalid S3 API responses, the error message will contain the raw response from the internal service, allowing access to internal resources. Mitigations
ImpactThis vulnerability has high severity as it allows authenticated users to make requests to arbitrary internal services from the application server, potentially exposing sensitive internal resources and bypassing network segmentation. The inclusion of response data in error messages makes this particularly effective for data exfiltration. Affected versions
0.4.1
0.4.2
0.4.3
0.4.4
0.4.4.post1
0.4.4.post2
0.4.5
0.4.6
0.4.6.post1
0.4.6.post2
0.4.7
0.4.8
+ 76 more Show less
0.5.0
0.5.1
0.6.0
0.6.1
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.4.post0
0.7.4.post1
0.7.5.post1
0.7.5.post2
0.8.0
0.8.0.post0
0.8.1
0.8.1.post0
0.8.2
0.8.2.post0
0.9.0
0.9.0.post2
0.9.0.post3
0.9.0.post4
0.9.0.post5
0.9.1
0.9.1.post0
0.9.1.post1
0.9.1.post2
1.0.0
1.0.0.post0
1.0.0.post1
1.0.0.post2
1.0.0.post3
1.0.1
1.0.2
1.0.2.post0
1.1.0
1.1.0rc0
1.1.1
1.10.0
1.10.0.post0
1.10.1
1.11.0
1.12.0
1.12.0.post0
1.12.1
1.13.0
1.13.1
1.14.0
1.14.0.post0
1.15.0
1.2
1.3
1.3.post0
1.3.post1
1.4
1.4.1
1.4.1.post0
1.4.1.post1
1.5.0
1.5.0.post0
1.6.0
1.7.0
1.7.1
1.7.2
1.7.3
1.8.0
1.8.1
1.8.2
1.8.2.post0
1.8.2.post1
1.9.0
1.9.1
1.9.1.post0
1.9.2
1.9.2.post0
Fixed in
1.16.0
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-25296
PYSEC-2026-1504
GHSA-wpq5-3366-mqw4
Jul 07, 2026
Label Studio allows Cross-Site Scripting (XSS) via GET request to `/projects/upload-example` endpoint
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
DescriptionLabel Studio's The vulnerability exists because the upload-example endpoint renders user-provided HTML content without proper sanitization on a GET request. This allows attackers to inject and execute arbitrary JavaScript in victims' browsers by getting them to visit a maliciously crafted URL. This is considered vulnerable because it enables attackers to execute JavaScript in victims' contexts, potentially allowing theft of sensitive data, session hijacking, or other malicious actions. Steps to reproduce
When executed, the payload causes the application to render an HTML page containing an img tag that fails to load, triggering the onerror event handler which executes base64-decoded JavaScript, demonstrating successful XSS execution in the victim's browser. Mitigations
ImpactThe vulnerability requires no special privileges and can be exploited by getting a victim to visit a crafted URL. The impact is high as it allows arbitrary JavaScript execution in victims' browsers, potentially exposing sensitive data or enabling account takeover through session theft. Affected versions
0.4.1
0.4.2
0.4.3
0.4.4
0.4.4.post1
0.4.4.post2
0.4.5
0.4.6
0.4.6.post1
0.4.6.post2
0.4.7
0.4.8
+ 76 more Show less
0.5.0
0.5.1
0.6.0
0.6.1
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.4.post0
0.7.4.post1
0.7.5.post1
0.7.5.post2
0.8.0
0.8.0.post0
0.8.1
0.8.1.post0
0.8.2
0.8.2.post0
0.9.0
0.9.0.post2
0.9.0.post3
0.9.0.post4
0.9.0.post5
0.9.1
0.9.1.post0
0.9.1.post1
0.9.1.post2
1.0.0
1.0.0.post0
1.0.0.post1
1.0.0.post2
1.0.0.post3
1.0.1
1.0.2
1.0.2.post0
1.1.0
1.1.0rc0
1.1.1
1.10.0
1.10.0.post0
1.10.1
1.11.0
1.12.0
1.12.0.post0
1.12.1
1.13.0
1.13.1
1.14.0
1.14.0.post0
1.15.0
1.2
1.3
1.3.post0
1.3.post1
1.4
1.4.1
1.4.1.post0
1.4.1.post1
1.5.0
1.5.0.post0
1.6.0
1.7.0
1.7.1
1.7.2
1.7.3
1.8.0
1.8.1
1.8.2
1.8.2.post0
1.8.2.post1
1.9.0
1.9.1
1.9.1.post0
1.9.2
1.9.2.post0
Fixed in
1.16.0
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-47783
GHSA-8jhr-wpcm-hh4h
PYSEC-2025-124
May 15, 2025
label-studio vulnerable to Cross-Site Scripting (Reflected) via the label_config parameter.
High
Network
Low
None
SummaryThe vulnerability allows an attacker to inject a malicious script into the context of a web page, which can lead to data theft, unauthorized actions on behalf of the user, and other attacks. DetailsThe vulnerability is reproducible when sending a properly formatted request to the
The vulnerability is specifically located in line 57, where HttpResponse is used.
PoCSend the following request after changing the
Or you can create a vulnerable HTML page by changing
Impact
Affected versions
0.4.1
0.4.2
0.4.3
0.4.4
0.4.4.post1
0.4.4.post2
0.4.5
0.4.6
0.4.6.post1
0.4.6.post2
0.4.7
0.4.8
+ 78 more Show less
0.5.0
0.5.1
0.6.0
0.6.1
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.4.post0
0.7.4.post1
0.7.5.post1
0.7.5.post2
0.8.0
0.8.0.post0
0.8.1
0.8.1.post0
0.8.2
0.8.2.post0
0.9.0
0.9.0.post2
0.9.0.post3
0.9.0.post4
0.9.0.post5
0.9.1
0.9.1.post0
0.9.1.post1
0.9.1.post2
1.0.0
1.0.0.post0
1.0.0.post1
1.0.0.post2
1.0.0.post3
1.0.1
1.0.2
1.0.2.post0
1.1.0
1.1.0rc0
1.1.1
1.10.0
1.10.0.post0
1.10.1
1.11.0
1.12.0
1.12.0.post0
1.12.1
1.13.0
1.13.1
1.14.0
1.14.0.post0
1.15.0
1.16.0
1.17.0
1.2
1.3
1.3.post0
1.3.post1
1.4
1.4.1
1.4.1.post0
1.4.1.post1
1.5.0
1.5.0.post0
1.6.0
1.7.0
1.7.1
1.7.2
1.7.3
1.8.0
1.8.1
1.8.2
1.8.2.post0
1.8.2.post1
1.9.0
1.9.1
1.9.1.post0
1.9.2
1.9.2.post0
Fixed in
1.18.0
References
Updated Jun 06, 2026 · Source: OSV.dev
CVE-2024-26152
PYSEC-2024-249
GHSA-6xv9-957j-qfhg
Feb 22, 2024
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
SummaryOn all Label Studio versions prior to 1.11.0, data imported via file upload feature is not properly sanitized prior to being rendered within a DetailsNeed permission to use the "data import" function. This was reproduced on Label Studio 1.10.1. PoC
The following are the contents of the files used in the PoC
ImpactMalicious scripts can be injected into the code, and when linked with vulnerabilities such as CSRF, it can cause even greater damage. In particular, It can become a source of further attacks, especially when linked to social engineering. Affected versions
0.4.1
0.4.2
0.4.3
0.4.4
0.4.4.post1
0.4.4.post2
0.4.5
0.4.6
0.4.6.post1
0.4.6.post2
0.4.7
0.4.8
+ 113 more Show less
0.5.0
0.5.1
0.6.0
0.6.1
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.4.post0
0.7.4.post1
0.7.5.post1
0.7.5.post2
0.8.0
0.8.0.post0
0.8.1
0.8.1.post0
0.8.2
0.8.2.post0
0.9.0
0.9.0.post2
0.9.0.post3
0.9.0.post4
0.9.0.post5
0.9.1
0.9.1.post0
0.9.1.post1
0.9.1.post2
1.0.0
1.0.0.post0
1.0.0.post1
1.0.0.post2
1.0.0.post3
1.0.1
1.0.2
1.0.2.post0
1.1.0
1.1.0rc0
1.1.1
1.10.0
1.10.0.post0
1.10.1
1.2
1.3
1.3.post0
1.3.post1
1.4
1.4.1
1.4.1.post0
1.4.1.post1
1.5.0
1.5.0.post0
1.6.0
1.7.0
1.7.1
1.7.2
1.7.3
1.8.0
1.8.1
1.8.2
1.8.2.post0
1.8.2.post1
1.9.0
1.9.1
1.9.1.post0
1.9.2
1.9.2.post0
v1.4.1
v1.4.0
v1.3.0
v1.2.0
v1.1.1
v1.1.0
v1.0.2
v1.0.1
v1.0.0
v0.9.1.post1
v0.9.1.post0
v0.9.0.post5
v0.9.0.post4
v0.9.0.post3
v0.9.0
v0.8.2
v0.8.1
v0.8.0
v0.7.5.post0
v0.7.3
v0.7.2
v0.7.1
v0.7.0
v0.6.1
v0.6.0
v0.5.1
v0.4.8
v0.4.7
v0.4.6
v0.4.5
v0.4.4
v0.4.0
v0.3.0
v0.2.2
v.0.2.1-8
v.0.2.1-5
v.0.2.1-4
v.0.2.1-3
v.0.2.1-2
v.0.2.0
v.0.1.6
v.0.1.5
v.0.1.4
v.0.1.2
v.0.1.1
v.0.1.0
Fixed in
1.11.0
References
Updated Jun 10, 2026 · Source: OSV.dev
CVE-2023-47116
GHSA-p59w-9gqw-wj8r
PYSEC-2024-127
Jan 31, 2024
Label Studio SSRF on Import Bypassing `SSRF_PROTECTION_ENABLED` Protections
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
IntroductionThis write-up describes a vulnerability found in Label Studio, a popular open source data labeling tool. The vulnerability affects all versions of Label Studio prior to OverviewLabel Studio's SSRF protections that can be enabled by setting the DescriptionThe following
The
The issue here is the SSRF validation is only performed before the request is sent, and does not validate the destination IP address. Therefore, an attacker can either redirect the request or perform a DNS rebinding attack to bypass this protection. Proof of ConceptBoth the HTTP redirection and DNS rebinding methods for bypassing Label Studio's SSRF protections are explained below. HTTP RedirectionThe python
DNS Rebinding AttackDNS rebinding can bypass SSRF protections by resolving to an external IP address for the first resolution, but when the request is sent resolves to an internal IP address that is blocked. For an example, the domain ImpactSSRF vulnerabilities pose a significant risk on cloud environments, since instance credentials are managed by internal web APIs. An attacker can bypass Label Studio's SSRF protections to access internal web servers and partially compromise the confidentiality of those internal servers. Remediation Advice
Discovered
Affected versions
0.4.1
0.4.2
0.4.3
0.4.4
0.4.4.post1
0.4.4.post2
0.4.5
0.4.6
0.4.6.post1
0.4.6.post2
0.4.7
0.4.8
+ 67 more Show less
0.5.0
0.5.1
0.6.0
0.6.1
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.4.post0
0.7.4.post1
0.7.5.post1
0.7.5.post2
0.8.0
0.8.0.post0
0.8.1
0.8.1.post0
0.8.2
0.8.2.post0
0.9.0
0.9.0.post2
0.9.0.post3
0.9.0.post4
0.9.0.post5
0.9.1
0.9.1.post0
0.9.1.post1
0.9.1.post2
1.0.0
1.0.0.post0
1.0.0.post1
1.0.0.post2
1.0.0.post3
1.0.1
1.0.2
1.0.2.post0
1.1.0
1.1.0rc0
1.1.1
1.10.0
1.10.0.post0
1.10.1
1.2
1.3
1.3.post0
1.3.post1
1.4
1.4.1
1.4.1.post0
1.4.1.post1
1.5.0
1.5.0.post0
1.6.0
1.7.0
1.7.1
1.7.2
1.7.3
1.8.0
1.8.1
1.8.2
1.8.2.post0
1.8.2.post1
1.9.0
1.9.1
1.9.1.post0
1.9.2
1.9.2.post0
Fixed in
1.11.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-23633
GHSA-fq23-g58m-799r
PYSEC-2024-128
Jan 24, 2024
Cross-site Scripting Vulnerability on Data Import
4.7
/ 10
Medium
Network
Low
None
Required
Changed
Low
None
None
IntroductionThis write-up describes a vulnerability found in Label Studio, a popular open source data labeling tool. The vulnerability affects all versions of Label Studio prior to OverviewLabel Studio had a remote import feature allowed users to import data from a remote web source, that was downloaded and could be viewed on the website. This feature could had been abused to download a HTML file that executed malicious JavaScript code in the context of the Label Studio website. DescriptionThe following code snippet in Label Studio showed that is a URL passed the SSRF verification checks, the contents of the file would be downloaded using the filename in the URL.
The downloaded file path could then be retrieved by sending a request to
Since the Proof of ConceptBelow were the steps to recreate this issue:
ImpactExecuting arbitrary JavaScript could result in an attacker performing malicious actions on Label Studio users if they visit the crafted avatar image. For an example, an attacker can craft a JavaScript payload that adds a new Django Super Administrator user if a Django administrator visits the image. Remediation Advice
Discovered
Affected versions
0.4.1
0.4.2
0.4.3
0.4.4
0.4.4.post1
0.4.4.post2
0.4.5
0.4.6
0.4.6.post1
0.4.6.post2
0.4.7
0.4.8
+ 66 more Show less
0.5.0
0.5.1
0.6.0
0.6.1
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.4.post0
0.7.4.post1
0.7.5.post1
0.7.5.post2
0.8.0
0.8.0.post0
0.8.1
0.8.1.post0
0.8.2
0.8.2.post0
0.9.0
0.9.0.post2
0.9.0.post3
0.9.0.post4
0.9.0.post5
0.9.1
0.9.1.post0
0.9.1.post1
0.9.1.post2
1.0.0
1.0.0.post0
1.0.0.post1
1.0.0.post2
1.0.0.post3
1.0.1
1.0.2
1.0.2.post0
1.1.0
1.1.0rc0
1.1.1
1.10.0
1.10.0.post0
1.2
1.3
1.3.post0
1.3.post1
1.4
1.4.1
1.4.1.post0
1.4.1.post1
1.5.0
1.5.0.post0
1.6.0
1.7.0
1.7.1
1.7.2
1.7.3
1.8.0
1.8.1
1.8.2
1.8.2.post0
1.8.2.post1
1.9.0
1.9.1
1.9.1.post0
1.9.2
1.9.2.post0
Fixed in
1.10.1
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2023-47115
GHSA-q68h-xwq5-mm7x
PYSEC-2024-126
Jan 24, 2024
Cross-site Scripting Vulnerability on Avatar Upload
7.1
/ 10
High
Network
Low
None
Required
Changed
Low
Low
Low
IntroductionThis write-up describes a vulnerability found in Label Studio, a popular open source data labeling tool. The vulnerability affects all versions of Label Studio prior to OverviewLabel Studio has a cross-site scripting (XSS) vulnerability that could be exploited when an authenticated user uploads a crafted image file for their avatar that gets rendered as a HTML file on the website. DescriptionThe following code snippet in Label Studio shows that the only verification check is that the file is an image by extracting the dimensions from the file.
Label Studio serves avatar images using Django's built-in
The issue with the Django Proof of ConceptBelow are the steps to reproduce this issue and execute JavaScript code in the context of the Label Studio website.
ImpactExecuting arbitrary JavaScript could result in an attacker performing malicious actions on Label Studio users if they visit the crafted avatar image. For an example, an attacker can craft a JavaScript payload that adds a new Django Super Administrator user if a Django administrator visits the image. Remediation Advice
Discovered
Affected versions
0.4.1
0.4.2
0.4.3
0.4.4
0.4.4.post1
0.4.4.post2
0.4.5
0.4.6
0.4.6.post1
0.4.6.post2
0.4.7
0.4.8
+ 62 more Show less
0.5.0
0.5.1
0.6.0
0.6.1
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.4.post0
0.7.4.post1
0.7.5.post1
0.7.5.post2
0.8.0
0.8.0.post0
0.8.1
0.8.1.post0
0.8.2
0.8.2.post0
0.9.0
0.9.0.post2
0.9.0.post3
0.9.0.post4
0.9.0.post5
0.9.1
0.9.1.post0
0.9.1.post1
0.9.1.post2
1.0.0
1.0.0.post0
1.0.0.post1
1.0.0.post2
1.0.0.post3
1.0.1
1.0.2
1.0.2.post0
1.1.0
1.1.0rc0
1.1.1
1.2
1.3
1.3.post0
1.3.post1
1.4
1.4.1
1.4.1.post0
1.4.1.post1
1.5.0
1.5.0.post0
1.6.0
1.7.0
1.7.1
1.7.2
1.7.3
1.8.0
1.8.1
1.8.2
1.8.2.post0
1.8.2.post1
1.9.0
1.9.1
1.9.1.post0
Fixed in
1.9.2
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2023-47117
GHSA-6hjj-gq77-j4qw
PYSEC-2023-275
Nov 14, 2023
Label Studio Object Relational Mapper Leak Vulnerability in Filtering Task
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
IntroductionThis write-up describes a vulnerability found in Label Studio, a popular open source data labeling tool. The vulnerability affects all versions of Label Studio prior to OverviewIn all current versions of Label Studio, the application allows users to insecurely set filters for filtering tasks. An attacker can construct a filter chain to filter tasks based on sensitive fields for all user accounts on the platform by exploiting Django's Object Relational Mapper (ORM). Since the results of query can be manipulated by the ORM filter, an attacker can leak these sensitive fields character by character. For an example, the following filter chain will task results by the password hash of an account on Label Studio.
For consistency, this type of vulnerability will be termed as ORM Leak in the rest of this disclosure. In addition, Label Studio had a hard coded secret key that an attacker can use to forge a session token of any user by exploiting this ORM Leak vulnerability to leak account password hashes. DescriptionThe following code snippet from the
These
The
The following code snippet of the
Finally, the
Proof of ConceptBelow are the steps to exploit about how to exploit this vulnerability to leak the password hash of an account on Label Studio.
The following example GIF demonstrates exploiting this ORM Leak vulnerability to retrieve the password hash
ImpactThis vulnerability can be exploited to completely compromise the confidentiality of highly sensitive account information, such as account password hashes. For all versions Remediation Advice
Discovered
| ||
1.7.0
minor
11 CVEs
CVE-2026-22033
PYSEC-2026-1502
GHSA-2mq9-hm29-8qch
Jul 07, 2026
Label Studio is vulnerable to full account takeover by chaining Stored XSS + IDOR in User Profile via custom_hotkeys field
Critical
Network
Low
Low
None
PrologueThese vulnerabilities have been found and chained by DCODX-AI. Validation of the exploit chain has been confirmed manually. SummaryA persistent stored cross-site scripting (XSS) vulnerability exists in the custom_hotkeys functionality of the application. An authenticated attacker (or one who can trick a user/administrator into updating their custom_hotkeys) can inject JavaScript code that executes in other users’ browsers when those users load any page using the DetailsWithin
Here, user.custom_hotkeys is run through json_dumps_ensure_ascii (in In
The serializer allows
When another user loads a page using templates/base.html (for example PoC
Example request
Example response
ImpactExploitation impact:
Who is impacted:
Affected versions
0.4.1
0.4.2
0.4.3
0.4.4
0.4.4.post1
0.4.4.post2
0.4.5
0.4.6
0.4.6.post1
0.4.6.post2
0.4.7
0.4.8
+ 83 more Show less
0.5.0
0.5.1
0.6.0
0.6.1
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.4.post0
0.7.4.post1
0.7.5.post1
0.7.5.post2
0.8.0
0.8.0.post0
0.8.1
0.8.1.post0
0.8.2
0.8.2.post0
0.9.0
0.9.0.post2
0.9.0.post3
0.9.0.post4
0.9.0.post5
0.9.1
0.9.1.post0
0.9.1.post1
0.9.1.post2
1.0.0
1.0.0.post0
1.0.0.post1
1.0.0.post2
1.0.0.post3
1.0.1
1.0.2
1.0.2.post0
1.1.0
1.1.0rc0
1.1.1
1.10.0
1.10.0.post0
1.10.1
1.11.0
1.12.0
1.12.0.post0
1.12.1
1.13.0
1.13.1
1.14.0
1.14.0.post0
1.15.0
1.16.0
1.17.0
1.18.0
1.19.0
1.2
1.20.0
1.21.0
1.22.0
1.3
1.3.post0
1.3.post1
1.4
1.4.1
1.4.1.post0
1.4.1.post1
1.5.0
1.5.0.post0
1.6.0
1.7.0
1.7.1
1.7.2
1.7.3
1.8.0
1.8.1
1.8.2
1.8.2.post0
1.8.2.post1
1.9.0
1.9.1
1.9.1.post0
1.9.2
1.9.2.post0
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-25297
PYSEC-2026-1503
GHSA-m238-fmcw-wh58
Jul 07, 2026
Label Studio allows Server-Side Request Forgery in the S3 Storage Endpoint
8.6
/ 10
High
Network
Low
None
None
Changed
High
None
None
DescriptionLabel Studio's S3 storage integration feature contains a Server-Side Request Forgery (SSRF) vulnerability in its endpoint configuration. When creating an S3 storage connection, the application allows users to specify a custom S3 endpoint URL via the s3_endpoint parameter. This endpoint URL is passed directly to the boto3 AWS SDK without proper validation or restrictions on the protocol or destination. The vulnerability allows an attacker to make the application send HTTP requests to arbitrary internal services by specifying them as the S3 endpoint. When the storage sync operation is triggered, the application attempts to make S3 API calls to the specified endpoint, effectively making HTTP requests to the target service and returning the response in error messages. This SSRF vulnerability enables attackers to bypass network segmentation and access internal services that should not be accessible from the external network. The vulnerability is particularly severe because error messages from failed requests contain the full response body, allowing data exfiltration from internal services. Steps to reproduce
The application will attempt to connect to the specified endpoint URL as if it were an S3 service. When the request fails due to invalid S3 API responses, the error message will contain the raw response from the internal service, allowing access to internal resources. Mitigations
ImpactThis vulnerability has high severity as it allows authenticated users to make requests to arbitrary internal services from the application server, potentially exposing sensitive internal resources and bypassing network segmentation. The inclusion of response data in error messages makes this particularly effective for data exfiltration. Affected versions
0.4.1
0.4.2
0.4.3
0.4.4
0.4.4.post1
0.4.4.post2
0.4.5
0.4.6
0.4.6.post1
0.4.6.post2
0.4.7
0.4.8
+ 76 more Show less
0.5.0
0.5.1
0.6.0
0.6.1
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.4.post0
0.7.4.post1
0.7.5.post1
0.7.5.post2
0.8.0
0.8.0.post0
0.8.1
0.8.1.post0
0.8.2
0.8.2.post0
0.9.0
0.9.0.post2
0.9.0.post3
0.9.0.post4
0.9.0.post5
0.9.1
0.9.1.post0
0.9.1.post1
0.9.1.post2
1.0.0
1.0.0.post0
1.0.0.post1
1.0.0.post2
1.0.0.post3
1.0.1
1.0.2
1.0.2.post0
1.1.0
1.1.0rc0
1.1.1
1.10.0
1.10.0.post0
1.10.1
1.11.0
1.12.0
1.12.0.post0
1.12.1
1.13.0
1.13.1
1.14.0
1.14.0.post0
1.15.0
1.2
1.3
1.3.post0
1.3.post1
1.4
1.4.1
1.4.1.post0
1.4.1.post1
1.5.0
1.5.0.post0
1.6.0
1.7.0
1.7.1
1.7.2
1.7.3
1.8.0
1.8.1
1.8.2
1.8.2.post0
1.8.2.post1
1.9.0
1.9.1
1.9.1.post0
1.9.2
1.9.2.post0
Fixed in
1.16.0
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-25296
PYSEC-2026-1504
GHSA-wpq5-3366-mqw4
Jul 07, 2026
Label Studio allows Cross-Site Scripting (XSS) via GET request to `/projects/upload-example` endpoint
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
DescriptionLabel Studio's The vulnerability exists because the upload-example endpoint renders user-provided HTML content without proper sanitization on a GET request. This allows attackers to inject and execute arbitrary JavaScript in victims' browsers by getting them to visit a maliciously crafted URL. This is considered vulnerable because it enables attackers to execute JavaScript in victims' contexts, potentially allowing theft of sensitive data, session hijacking, or other malicious actions. Steps to reproduce
When executed, the payload causes the application to render an HTML page containing an img tag that fails to load, triggering the onerror event handler which executes base64-decoded JavaScript, demonstrating successful XSS execution in the victim's browser. Mitigations
ImpactThe vulnerability requires no special privileges and can be exploited by getting a victim to visit a crafted URL. The impact is high as it allows arbitrary JavaScript execution in victims' browsers, potentially exposing sensitive data or enabling account takeover through session theft. Affected versions
0.4.1
0.4.2
0.4.3
0.4.4
0.4.4.post1
0.4.4.post2
0.4.5
0.4.6
0.4.6.post1
0.4.6.post2
0.4.7
0.4.8
+ 76 more Show less
0.5.0
0.5.1
0.6.0
0.6.1
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.4.post0
0.7.4.post1
0.7.5.post1
0.7.5.post2
0.8.0
0.8.0.post0
0.8.1
0.8.1.post0
0.8.2
0.8.2.post0
0.9.0
0.9.0.post2
0.9.0.post3
0.9.0.post4
0.9.0.post5
0.9.1
0.9.1.post0
0.9.1.post1
0.9.1.post2
1.0.0
1.0.0.post0
1.0.0.post1
1.0.0.post2
1.0.0.post3
1.0.1
1.0.2
1.0.2.post0
1.1.0
1.1.0rc0
1.1.1
1.10.0
1.10.0.post0
1.10.1
1.11.0
1.12.0
1.12.0.post0
1.12.1
1.13.0
1.13.1
1.14.0
1.14.0.post0
1.15.0
1.2
1.3
1.3.post0
1.3.post1
1.4
1.4.1
1.4.1.post0
1.4.1.post1
1.5.0
1.5.0.post0
1.6.0
1.7.0
1.7.1
1.7.2
1.7.3
1.8.0
1.8.1
1.8.2
1.8.2.post0
1.8.2.post1
1.9.0
1.9.1
1.9.1.post0
1.9.2
1.9.2.post0
Fixed in
1.16.0
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-47783
GHSA-8jhr-wpcm-hh4h
PYSEC-2025-124
May 15, 2025
label-studio vulnerable to Cross-Site Scripting (Reflected) via the label_config parameter.
High
Network
Low
None
SummaryThe vulnerability allows an attacker to inject a malicious script into the context of a web page, which can lead to data theft, unauthorized actions on behalf of the user, and other attacks. DetailsThe vulnerability is reproducible when sending a properly formatted request to the
The vulnerability is specifically located in line 57, where HttpResponse is used.
PoCSend the following request after changing the
Or you can create a vulnerable HTML page by changing
Impact
Affected versions
0.4.1
0.4.2
0.4.3
0.4.4
0.4.4.post1
0.4.4.post2
0.4.5
0.4.6
0.4.6.post1
0.4.6.post2
0.4.7
0.4.8
+ 78 more Show less
0.5.0
0.5.1
0.6.0
0.6.1
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.4.post0
0.7.4.post1
0.7.5.post1
0.7.5.post2
0.8.0
0.8.0.post0
0.8.1
0.8.1.post0
0.8.2
0.8.2.post0
0.9.0
0.9.0.post2
0.9.0.post3
0.9.0.post4
0.9.0.post5
0.9.1
0.9.1.post0
0.9.1.post1
0.9.1.post2
1.0.0
1.0.0.post0
1.0.0.post1
1.0.0.post2
1.0.0.post3
1.0.1
1.0.2
1.0.2.post0
1.1.0
1.1.0rc0
1.1.1
1.10.0
1.10.0.post0
1.10.1
1.11.0
1.12.0
1.12.0.post0
1.12.1
1.13.0
1.13.1
1.14.0
1.14.0.post0
1.15.0
1.16.0
1.17.0
1.2
1.3
1.3.post0
1.3.post1
1.4
1.4.1
1.4.1.post0
1.4.1.post1
1.5.0
1.5.0.post0
1.6.0
1.7.0
1.7.1
1.7.2
1.7.3
1.8.0
1.8.1
1.8.2
1.8.2.post0
1.8.2.post1
1.9.0
1.9.1
1.9.1.post0
1.9.2
1.9.2.post0
Fixed in
1.18.0
References
Updated Jun 06, 2026 · Source: OSV.dev
CVE-2024-26152
PYSEC-2024-249
GHSA-6xv9-957j-qfhg
Feb 22, 2024
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
SummaryOn all Label Studio versions prior to 1.11.0, data imported via file upload feature is not properly sanitized prior to being rendered within a DetailsNeed permission to use the "data import" function. This was reproduced on Label Studio 1.10.1. PoC
The following are the contents of the files used in the PoC
ImpactMalicious scripts can be injected into the code, and when linked with vulnerabilities such as CSRF, it can cause even greater damage. In particular, It can become a source of further attacks, especially when linked to social engineering. Affected versions
0.4.1
0.4.2
0.4.3
0.4.4
0.4.4.post1
0.4.4.post2
0.4.5
0.4.6
0.4.6.post1
0.4.6.post2
0.4.7
0.4.8
+ 113 more Show less
0.5.0
0.5.1
0.6.0
0.6.1
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.4.post0
0.7.4.post1
0.7.5.post1
0.7.5.post2
0.8.0
0.8.0.post0
0.8.1
0.8.1.post0
0.8.2
0.8.2.post0
0.9.0
0.9.0.post2
0.9.0.post3
0.9.0.post4
0.9.0.post5
0.9.1
0.9.1.post0
0.9.1.post1
0.9.1.post2
1.0.0
1.0.0.post0
1.0.0.post1
1.0.0.post2
1.0.0.post3
1.0.1
1.0.2
1.0.2.post0
1.1.0
1.1.0rc0
1.1.1
1.10.0
1.10.0.post0
1.10.1
1.2
1.3
1.3.post0
1.3.post1
1.4
1.4.1
1.4.1.post0
1.4.1.post1
1.5.0
1.5.0.post0
1.6.0
1.7.0
1.7.1
1.7.2
1.7.3
1.8.0
1.8.1
1.8.2
1.8.2.post0
1.8.2.post1
1.9.0
1.9.1
1.9.1.post0
1.9.2
1.9.2.post0
v1.4.1
v1.4.0
v1.3.0
v1.2.0
v1.1.1
v1.1.0
v1.0.2
v1.0.1
v1.0.0
v0.9.1.post1
v0.9.1.post0
v0.9.0.post5
v0.9.0.post4
v0.9.0.post3
v0.9.0
v0.8.2
v0.8.1
v0.8.0
v0.7.5.post0
v0.7.3
v0.7.2
v0.7.1
v0.7.0
v0.6.1
v0.6.0
v0.5.1
v0.4.8
v0.4.7
v0.4.6
v0.4.5
v0.4.4
v0.4.0
v0.3.0
v0.2.2
v.0.2.1-8
v.0.2.1-5
v.0.2.1-4
v.0.2.1-3
v.0.2.1-2
v.0.2.0
v.0.1.6
v.0.1.5
v.0.1.4
v.0.1.2
v.0.1.1
v.0.1.0
Fixed in
1.11.0
References
Updated Jun 10, 2026 · Source: OSV.dev
CVE-2023-47116
GHSA-p59w-9gqw-wj8r
PYSEC-2024-127
Jan 31, 2024
Label Studio SSRF on Import Bypassing `SSRF_PROTECTION_ENABLED` Protections
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
IntroductionThis write-up describes a vulnerability found in Label Studio, a popular open source data labeling tool. The vulnerability affects all versions of Label Studio prior to OverviewLabel Studio's SSRF protections that can be enabled by setting the DescriptionThe following
The
The issue here is the SSRF validation is only performed before the request is sent, and does not validate the destination IP address. Therefore, an attacker can either redirect the request or perform a DNS rebinding attack to bypass this protection. Proof of ConceptBoth the HTTP redirection and DNS rebinding methods for bypassing Label Studio's SSRF protections are explained below. HTTP RedirectionThe python
DNS Rebinding AttackDNS rebinding can bypass SSRF protections by resolving to an external IP address for the first resolution, but when the request is sent resolves to an internal IP address that is blocked. For an example, the domain ImpactSSRF vulnerabilities pose a significant risk on cloud environments, since instance credentials are managed by internal web APIs. An attacker can bypass Label Studio's SSRF protections to access internal web servers and partially compromise the confidentiality of those internal servers. Remediation Advice
Discovered
Affected versions
0.4.1
0.4.2
0.4.3
0.4.4
0.4.4.post1
0.4.4.post2
0.4.5
0.4.6
0.4.6.post1
0.4.6.post2
0.4.7
0.4.8
+ 67 more Show less
0.5.0
0.5.1
0.6.0
0.6.1
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.4.post0
0.7.4.post1
0.7.5.post1
0.7.5.post2
0.8.0
0.8.0.post0
0.8.1
0.8.1.post0
0.8.2
0.8.2.post0
0.9.0
0.9.0.post2
0.9.0.post3
0.9.0.post4
0.9.0.post5
0.9.1
0.9.1.post0
0.9.1.post1
0.9.1.post2
1.0.0
1.0.0.post0
1.0.0.post1
1.0.0.post2
1.0.0.post3
1.0.1
1.0.2
1.0.2.post0
1.1.0
1.1.0rc0
1.1.1
1.10.0
1.10.0.post0
1.10.1
1.2
1.3
1.3.post0
1.3.post1
1.4
1.4.1
1.4.1.post0
1.4.1.post1
1.5.0
1.5.0.post0
1.6.0
1.7.0
1.7.1
1.7.2
1.7.3
1.8.0
1.8.1
1.8.2
1.8.2.post0
1.8.2.post1
1.9.0
1.9.1
1.9.1.post0
1.9.2
1.9.2.post0
Fixed in
1.11.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-23633
GHSA-fq23-g58m-799r
PYSEC-2024-128
Jan 24, 2024
Cross-site Scripting Vulnerability on Data Import
4.7
/ 10
Medium
Network
Low
None
Required
Changed
Low
None
None
IntroductionThis write-up describes a vulnerability found in Label Studio, a popular open source data labeling tool. The vulnerability affects all versions of Label Studio prior to OverviewLabel Studio had a remote import feature allowed users to import data from a remote web source, that was downloaded and could be viewed on the website. This feature could had been abused to download a HTML file that executed malicious JavaScript code in the context of the Label Studio website. DescriptionThe following code snippet in Label Studio showed that is a URL passed the SSRF verification checks, the contents of the file would be downloaded using the filename in the URL.
The downloaded file path could then be retrieved by sending a request to
Since the Proof of ConceptBelow were the steps to recreate this issue:
ImpactExecuting arbitrary JavaScript could result in an attacker performing malicious actions on Label Studio users if they visit the crafted avatar image. For an example, an attacker can craft a JavaScript payload that adds a new Django Super Administrator user if a Django administrator visits the image. Remediation Advice
Discovered
Affected versions
0.4.1
0.4.2
0.4.3
0.4.4
0.4.4.post1
0.4.4.post2
0.4.5
0.4.6
0.4.6.post1
0.4.6.post2
0.4.7
0.4.8
+ 66 more Show less
0.5.0
0.5.1
0.6.0
0.6.1
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.4.post0
0.7.4.post1
0.7.5.post1
0.7.5.post2
0.8.0
0.8.0.post0
0.8.1
0.8.1.post0
0.8.2
0.8.2.post0
0.9.0
0.9.0.post2
0.9.0.post3
0.9.0.post4
0.9.0.post5
0.9.1
0.9.1.post0
0.9.1.post1
0.9.1.post2
1.0.0
1.0.0.post0
1.0.0.post1
1.0.0.post2
1.0.0.post3
1.0.1
1.0.2
1.0.2.post0
1.1.0
1.1.0rc0
1.1.1
1.10.0
1.10.0.post0
1.2
1.3
1.3.post0
1.3.post1
1.4
1.4.1
1.4.1.post0
1.4.1.post1
1.5.0
1.5.0.post0
1.6.0
1.7.0
1.7.1
1.7.2
1.7.3
1.8.0
1.8.1
1.8.2
1.8.2.post0
1.8.2.post1
1.9.0
1.9.1
1.9.1.post0
1.9.2
1.9.2.post0
Fixed in
1.10.1
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2023-47115
GHSA-q68h-xwq5-mm7x
PYSEC-2024-126
Jan 24, 2024
Cross-site Scripting Vulnerability on Avatar Upload
7.1
/ 10
High
Network
Low
None
Required
Changed
Low
Low
Low
IntroductionThis write-up describes a vulnerability found in Label Studio, a popular open source data labeling tool. The vulnerability affects all versions of Label Studio prior to OverviewLabel Studio has a cross-site scripting (XSS) vulnerability that could be exploited when an authenticated user uploads a crafted image file for their avatar that gets rendered as a HTML file on the website. DescriptionThe following code snippet in Label Studio shows that the only verification check is that the file is an image by extracting the dimensions from the file.
Label Studio serves avatar images using Django's built-in
The issue with the Django Proof of ConceptBelow are the steps to reproduce this issue and execute JavaScript code in the context of the Label Studio website.
ImpactExecuting arbitrary JavaScript could result in an attacker performing malicious actions on Label Studio users if they visit the crafted avatar image. For an example, an attacker can craft a JavaScript payload that adds a new Django Super Administrator user if a Django administrator visits the image. Remediation Advice
Discovered
Affected versions
0.4.1
0.4.2
0.4.3
0.4.4
0.4.4.post1
0.4.4.post2
0.4.5
0.4.6
0.4.6.post1
0.4.6.post2
0.4.7
0.4.8
+ 62 more Show less
0.5.0
0.5.1
0.6.0
0.6.1
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.4.post0
0.7.4.post1
0.7.5.post1
0.7.5.post2
0.8.0
0.8.0.post0
0.8.1
0.8.1.post0
0.8.2
0.8.2.post0
0.9.0
0.9.0.post2
0.9.0.post3
0.9.0.post4
0.9.0.post5
0.9.1
0.9.1.post0
0.9.1.post1
0.9.1.post2
1.0.0
1.0.0.post0
1.0.0.post1
1.0.0.post2
1.0.0.post3
1.0.1
1.0.2
1.0.2.post0
1.1.0
1.1.0rc0
1.1.1
1.2
1.3
1.3.post0
1.3.post1
1.4
1.4.1
1.4.1.post0
1.4.1.post1
1.5.0
1.5.0.post0
1.6.0
1.7.0
1.7.1
1.7.2
1.7.3
1.8.0
1.8.1
1.8.2
1.8.2.post0
1.8.2.post1
1.9.0
1.9.1
1.9.1.post0
Fixed in
1.9.2
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2023-47117
GHSA-6hjj-gq77-j4qw
PYSEC-2023-275
Nov 14, 2023
Label Studio Object Relational Mapper Leak Vulnerability in Filtering Task
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
IntroductionThis write-up describes a vulnerability found in Label Studio, a popular open source data labeling tool. The vulnerability affects all versions of Label Studio prior to OverviewIn all current versions of Label Studio, the application allows users to insecurely set filters for filtering tasks. An attacker can construct a filter chain to filter tasks based on sensitive fields for all user accounts on the platform by exploiting Django's Object Relational Mapper (ORM). Since the results of query can be manipulated by the ORM filter, an attacker can leak these sensitive fields character by character. For an example, the following filter chain will task results by the password hash of an account on Label Studio.
For consistency, this type of vulnerability will be termed as ORM Leak in the rest of this disclosure. In addition, Label Studio had a hard coded secret key that an attacker can use to forge a session token of any user by exploiting this ORM Leak vulnerability to leak account password hashes. DescriptionThe following code snippet from the
These
The
The following code snippet of the
Finally, the
Proof of ConceptBelow are the steps to exploit about how to exploit this vulnerability to leak the password hash of an account on Label Studio.
The following example GIF demonstrates exploiting this ORM Leak vulnerability to retrieve the password hash
ImpactThis vulnerability can be exploited to completely compromise the confidentiality of highly sensitive account information, such as account password hashes. For all versions Remediation Advice
Discovered
| ||
1.6.0
minor
11 CVEs
CVE-2026-22033
PYSEC-2026-1502
GHSA-2mq9-hm29-8qch
Jul 07, 2026
Label Studio is vulnerable to full account takeover by chaining Stored XSS + IDOR in User Profile via custom_hotkeys field
Critical
Network
Low
Low
None
PrologueThese vulnerabilities have been found and chained by DCODX-AI. Validation of the exploit chain has been confirmed manually. SummaryA persistent stored cross-site scripting (XSS) vulnerability exists in the custom_hotkeys functionality of the application. An authenticated attacker (or one who can trick a user/administrator into updating their custom_hotkeys) can inject JavaScript code that executes in other users’ browsers when those users load any page using the DetailsWithin
Here, user.custom_hotkeys is run through json_dumps_ensure_ascii (in In
The serializer allows
When another user loads a page using templates/base.html (for example PoC
Example request
Example response
ImpactExploitation impact:
Who is impacted:
Affected versions
0.4.1
0.4.2
0.4.3
0.4.4
0.4.4.post1
0.4.4.post2
0.4.5
0.4.6
0.4.6.post1
0.4.6.post2
0.4.7
0.4.8
+ 83 more Show less
0.5.0
0.5.1
0.6.0
0.6.1
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.4.post0
0.7.4.post1
0.7.5.post1
0.7.5.post2
0.8.0
0.8.0.post0
0.8.1
0.8.1.post0
0.8.2
0.8.2.post0
0.9.0
0.9.0.post2
0.9.0.post3
0.9.0.post4
0.9.0.post5
0.9.1
0.9.1.post0
0.9.1.post1
0.9.1.post2
1.0.0
1.0.0.post0
1.0.0.post1
1.0.0.post2
1.0.0.post3
1.0.1
1.0.2
1.0.2.post0
1.1.0
1.1.0rc0
1.1.1
1.10.0
1.10.0.post0
1.10.1
1.11.0
1.12.0
1.12.0.post0
1.12.1
1.13.0
1.13.1
1.14.0
1.14.0.post0
1.15.0
1.16.0
1.17.0
1.18.0
1.19.0
1.2
1.20.0
1.21.0
1.22.0
1.3
1.3.post0
1.3.post1
1.4
1.4.1
1.4.1.post0
1.4.1.post1
1.5.0
1.5.0.post0
1.6.0
1.7.0
1.7.1
1.7.2
1.7.3
1.8.0
1.8.1
1.8.2
1.8.2.post0
1.8.2.post1
1.9.0
1.9.1
1.9.1.post0
1.9.2
1.9.2.post0
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-25297
PYSEC-2026-1503
GHSA-m238-fmcw-wh58
Jul 07, 2026
Label Studio allows Server-Side Request Forgery in the S3 Storage Endpoint
8.6
/ 10
High
Network
Low
None
None
Changed
High
None
None
DescriptionLabel Studio's S3 storage integration feature contains a Server-Side Request Forgery (SSRF) vulnerability in its endpoint configuration. When creating an S3 storage connection, the application allows users to specify a custom S3 endpoint URL via the s3_endpoint parameter. This endpoint URL is passed directly to the boto3 AWS SDK without proper validation or restrictions on the protocol or destination. The vulnerability allows an attacker to make the application send HTTP requests to arbitrary internal services by specifying them as the S3 endpoint. When the storage sync operation is triggered, the application attempts to make S3 API calls to the specified endpoint, effectively making HTTP requests to the target service and returning the response in error messages. This SSRF vulnerability enables attackers to bypass network segmentation and access internal services that should not be accessible from the external network. The vulnerability is particularly severe because error messages from failed requests contain the full response body, allowing data exfiltration from internal services. Steps to reproduce
The application will attempt to connect to the specified endpoint URL as if it were an S3 service. When the request fails due to invalid S3 API responses, the error message will contain the raw response from the internal service, allowing access to internal resources. Mitigations
ImpactThis vulnerability has high severity as it allows authenticated users to make requests to arbitrary internal services from the application server, potentially exposing sensitive internal resources and bypassing network segmentation. The inclusion of response data in error messages makes this particularly effective for data exfiltration. Affected versions
0.4.1
0.4.2
0.4.3
0.4.4
0.4.4.post1
0.4.4.post2
0.4.5
0.4.6
0.4.6.post1
0.4.6.post2
0.4.7
0.4.8
+ 76 more Show less
0.5.0
0.5.1
0.6.0
0.6.1
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.4.post0
0.7.4.post1
0.7.5.post1
0.7.5.post2
0.8.0
0.8.0.post0
0.8.1
0.8.1.post0
0.8.2
0.8.2.post0
0.9.0
0.9.0.post2
0.9.0.post3
0.9.0.post4
0.9.0.post5
0.9.1
0.9.1.post0
0.9.1.post1
0.9.1.post2
1.0.0
1.0.0.post0
1.0.0.post1
1.0.0.post2
1.0.0.post3
1.0.1
1.0.2
1.0.2.post0
1.1.0
1.1.0rc0
1.1.1
1.10.0
1.10.0.post0
1.10.1
1.11.0
1.12.0
1.12.0.post0
1.12.1
1.13.0
1.13.1
1.14.0
1.14.0.post0
1.15.0
1.2
1.3
1.3.post0
1.3.post1
1.4
1.4.1
1.4.1.post0
1.4.1.post1
1.5.0
1.5.0.post0
1.6.0
1.7.0
1.7.1
1.7.2
1.7.3
1.8.0
1.8.1
1.8.2
1.8.2.post0
1.8.2.post1
1.9.0
1.9.1
1.9.1.post0
1.9.2
1.9.2.post0
Fixed in
1.16.0
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-25296
PYSEC-2026-1504
GHSA-wpq5-3366-mqw4
Jul 07, 2026
Label Studio allows Cross-Site Scripting (XSS) via GET request to `/projects/upload-example` endpoint
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
DescriptionLabel Studio's The vulnerability exists because the upload-example endpoint renders user-provided HTML content without proper sanitization on a GET request. This allows attackers to inject and execute arbitrary JavaScript in victims' browsers by getting them to visit a maliciously crafted URL. This is considered vulnerable because it enables attackers to execute JavaScript in victims' contexts, potentially allowing theft of sensitive data, session hijacking, or other malicious actions. Steps to reproduce
When executed, the payload causes the application to render an HTML page containing an img tag that fails to load, triggering the onerror event handler which executes base64-decoded JavaScript, demonstrating successful XSS execution in the victim's browser. Mitigations
ImpactThe vulnerability requires no special privileges and can be exploited by getting a victim to visit a crafted URL. The impact is high as it allows arbitrary JavaScript execution in victims' browsers, potentially exposing sensitive data or enabling account takeover through session theft. Affected versions
0.4.1
0.4.2
0.4.3
0.4.4
0.4.4.post1
0.4.4.post2
0.4.5
0.4.6
0.4.6.post1
0.4.6.post2
0.4.7
0.4.8
+ 76 more Show less
0.5.0
0.5.1
0.6.0
0.6.1
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.4.post0
0.7.4.post1
0.7.5.post1
0.7.5.post2
0.8.0
0.8.0.post0
0.8.1
0.8.1.post0
0.8.2
0.8.2.post0
0.9.0
0.9.0.post2
0.9.0.post3
0.9.0.post4
0.9.0.post5
0.9.1
0.9.1.post0
0.9.1.post1
0.9.1.post2
1.0.0
1.0.0.post0
1.0.0.post1
1.0.0.post2
1.0.0.post3
1.0.1
1.0.2
1.0.2.post0
1.1.0
1.1.0rc0
1.1.1
1.10.0
1.10.0.post0
1.10.1
1.11.0
1.12.0
1.12.0.post0
1.12.1
1.13.0
1.13.1
1.14.0
1.14.0.post0
1.15.0
1.2
1.3
1.3.post0
1.3.post1
1.4
1.4.1
1.4.1.post0
1.4.1.post1
1.5.0
1.5.0.post0
1.6.0
1.7.0
1.7.1
1.7.2
1.7.3
1.8.0
1.8.1
1.8.2
1.8.2.post0
1.8.2.post1
1.9.0
1.9.1
1.9.1.post0
1.9.2
1.9.2.post0
Fixed in
1.16.0
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-47783
GHSA-8jhr-wpcm-hh4h
PYSEC-2025-124
May 15, 2025
label-studio vulnerable to Cross-Site Scripting (Reflected) via the label_config parameter.
High
Network
Low
None
SummaryThe vulnerability allows an attacker to inject a malicious script into the context of a web page, which can lead to data theft, unauthorized actions on behalf of the user, and other attacks. DetailsThe vulnerability is reproducible when sending a properly formatted request to the
The vulnerability is specifically located in line 57, where HttpResponse is used.
PoCSend the following request after changing the
Or you can create a vulnerable HTML page by changing
Impact
Affected versions
0.4.1
0.4.2
0.4.3
0.4.4
0.4.4.post1
0.4.4.post2
0.4.5
0.4.6
0.4.6.post1
0.4.6.post2
0.4.7
0.4.8
+ 78 more Show less
0.5.0
0.5.1
0.6.0
0.6.1
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.4.post0
0.7.4.post1
0.7.5.post1
0.7.5.post2
0.8.0
0.8.0.post0
0.8.1
0.8.1.post0
0.8.2
0.8.2.post0
0.9.0
0.9.0.post2
0.9.0.post3
0.9.0.post4
0.9.0.post5
0.9.1
0.9.1.post0
0.9.1.post1
0.9.1.post2
1.0.0
1.0.0.post0
1.0.0.post1
1.0.0.post2
1.0.0.post3
1.0.1
1.0.2
1.0.2.post0
1.1.0
1.1.0rc0
1.1.1
1.10.0
1.10.0.post0
1.10.1
1.11.0
1.12.0
1.12.0.post0
1.12.1
1.13.0
1.13.1
1.14.0
1.14.0.post0
1.15.0
1.16.0
1.17.0
1.2
1.3
1.3.post0
1.3.post1
1.4
1.4.1
1.4.1.post0
1.4.1.post1
1.5.0
1.5.0.post0
1.6.0
1.7.0
1.7.1
1.7.2
1.7.3
1.8.0
1.8.1
1.8.2
1.8.2.post0
1.8.2.post1
1.9.0
1.9.1
1.9.1.post0
1.9.2
1.9.2.post0
Fixed in
1.18.0
References
Updated Jun 06, 2026 · Source: OSV.dev
CVE-2024-26152
PYSEC-2024-249
GHSA-6xv9-957j-qfhg
Feb 22, 2024
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
SummaryOn all Label Studio versions prior to 1.11.0, data imported via file upload feature is not properly sanitized prior to being rendered within a DetailsNeed permission to use the "data import" function. This was reproduced on Label Studio 1.10.1. PoC
The following are the contents of the files used in the PoC
ImpactMalicious scripts can be injected into the code, and when linked with vulnerabilities such as CSRF, it can cause even greater damage. In particular, It can become a source of further attacks, especially when linked to social engineering. Affected versions
0.4.1
0.4.2
0.4.3
0.4.4
0.4.4.post1
0.4.4.post2
0.4.5
0.4.6
0.4.6.post1
0.4.6.post2
0.4.7
0.4.8
+ 113 more Show less
0.5.0
0.5.1
0.6.0
0.6.1
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.4.post0
0.7.4.post1
0.7.5.post1
0.7.5.post2
0.8.0
0.8.0.post0
0.8.1
0.8.1.post0
0.8.2
0.8.2.post0
0.9.0
0.9.0.post2
0.9.0.post3
0.9.0.post4
0.9.0.post5
0.9.1
0.9.1.post0
0.9.1.post1
0.9.1.post2
1.0.0
1.0.0.post0
1.0.0.post1
1.0.0.post2
1.0.0.post3
1.0.1
1.0.2
1.0.2.post0
1.1.0
1.1.0rc0
1.1.1
1.10.0
1.10.0.post0
1.10.1
1.2
1.3
1.3.post0
1.3.post1
1.4
1.4.1
1.4.1.post0
1.4.1.post1
1.5.0
1.5.0.post0
1.6.0
1.7.0
1.7.1
1.7.2
1.7.3
1.8.0
1.8.1
1.8.2
1.8.2.post0
1.8.2.post1
1.9.0
1.9.1
1.9.1.post0
1.9.2
1.9.2.post0
v1.4.1
v1.4.0
v1.3.0
v1.2.0
v1.1.1
v1.1.0
v1.0.2
v1.0.1
v1.0.0
v0.9.1.post1
v0.9.1.post0
v0.9.0.post5
v0.9.0.post4
v0.9.0.post3
v0.9.0
v0.8.2
v0.8.1
v0.8.0
v0.7.5.post0
v0.7.3
v0.7.2
v0.7.1
v0.7.0
v0.6.1
v0.6.0
v0.5.1
v0.4.8
v0.4.7
v0.4.6
v0.4.5
v0.4.4
v0.4.0
v0.3.0
v0.2.2
v.0.2.1-8
v.0.2.1-5
v.0.2.1-4
v.0.2.1-3
v.0.2.1-2
v.0.2.0
v.0.1.6
v.0.1.5
v.0.1.4
v.0.1.2
v.0.1.1
v.0.1.0
Fixed in
1.11.0
References
Updated Jun 10, 2026 · Source: OSV.dev
CVE-2023-47116
GHSA-p59w-9gqw-wj8r
PYSEC-2024-127
Jan 31, 2024
Label Studio SSRF on Import Bypassing `SSRF_PROTECTION_ENABLED` Protections
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
IntroductionThis write-up describes a vulnerability found in Label Studio, a popular open source data labeling tool. The vulnerability affects all versions of Label Studio prior to OverviewLabel Studio's SSRF protections that can be enabled by setting the DescriptionThe following
The
The issue here is the SSRF validation is only performed before the request is sent, and does not validate the destination IP address. Therefore, an attacker can either redirect the request or perform a DNS rebinding attack to bypass this protection. Proof of ConceptBoth the HTTP redirection and DNS rebinding methods for bypassing Label Studio's SSRF protections are explained below. HTTP RedirectionThe python
DNS Rebinding AttackDNS rebinding can bypass SSRF protections by resolving to an external IP address for the first resolution, but when the request is sent resolves to an internal IP address that is blocked. For an example, the domain ImpactSSRF vulnerabilities pose a significant risk on cloud environments, since instance credentials are managed by internal web APIs. An attacker can bypass Label Studio's SSRF protections to access internal web servers and partially compromise the confidentiality of those internal servers. Remediation Advice
Discovered
Affected versions
0.4.1
0.4.2
0.4.3
0.4.4
0.4.4.post1
0.4.4.post2
0.4.5
0.4.6
0.4.6.post1
0.4.6.post2
0.4.7
0.4.8
+ 67 more Show less
0.5.0
0.5.1
0.6.0
0.6.1
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.4.post0
0.7.4.post1
0.7.5.post1
0.7.5.post2
0.8.0
0.8.0.post0
0.8.1
0.8.1.post0
0.8.2
0.8.2.post0
0.9.0
0.9.0.post2
0.9.0.post3
0.9.0.post4
0.9.0.post5
0.9.1
0.9.1.post0
0.9.1.post1
0.9.1.post2
1.0.0
1.0.0.post0
1.0.0.post1
1.0.0.post2
1.0.0.post3
1.0.1
1.0.2
1.0.2.post0
1.1.0
1.1.0rc0
1.1.1
1.10.0
1.10.0.post0
1.10.1
1.2
1.3
1.3.post0
1.3.post1
1.4
1.4.1
1.4.1.post0
1.4.1.post1
1.5.0
1.5.0.post0
1.6.0
1.7.0
1.7.1
1.7.2
1.7.3
1.8.0
1.8.1
1.8.2
1.8.2.post0
1.8.2.post1
1.9.0
1.9.1
1.9.1.post0
1.9.2
1.9.2.post0
Fixed in
1.11.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-23633
GHSA-fq23-g58m-799r
PYSEC-2024-128
Jan 24, 2024
Cross-site Scripting Vulnerability on Data Import
4.7
/ 10
Medium
Network
Low
None
Required
Changed
Low
None
None
IntroductionThis write-up describes a vulnerability found in Label Studio, a popular open source data labeling tool. The vulnerability affects all versions of Label Studio prior to OverviewLabel Studio had a remote import feature allowed users to import data from a remote web source, that was downloaded and could be viewed on the website. This feature could had been abused to download a HTML file that executed malicious JavaScript code in the context of the Label Studio website. DescriptionThe following code snippet in Label Studio showed that is a URL passed the SSRF verification checks, the contents of the file would be downloaded using the filename in the URL.
The downloaded file path could then be retrieved by sending a request to
Since the Proof of ConceptBelow were the steps to recreate this issue:
ImpactExecuting arbitrary JavaScript could result in an attacker performing malicious actions on Label Studio users if they visit the crafted avatar image. For an example, an attacker can craft a JavaScript payload that adds a new Django Super Administrator user if a Django administrator visits the image. Remediation Advice
Discovered
Affected versions
0.4.1
0.4.2
0.4.3
0.4.4
0.4.4.post1
0.4.4.post2
0.4.5
0.4.6
0.4.6.post1
0.4.6.post2
0.4.7
0.4.8
+ 66 more Show less
0.5.0
0.5.1
0.6.0
0.6.1
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.4.post0
0.7.4.post1
0.7.5.post1
0.7.5.post2
0.8.0
0.8.0.post0
0.8.1
0.8.1.post0
0.8.2
0.8.2.post0
0.9.0
0.9.0.post2
0.9.0.post3
0.9.0.post4
0.9.0.post5
0.9.1
0.9.1.post0
0.9.1.post1
0.9.1.post2
1.0.0
1.0.0.post0
1.0.0.post1
1.0.0.post2
1.0.0.post3
1.0.1
1.0.2
1.0.2.post0
1.1.0
1.1.0rc0
1.1.1
1.10.0
1.10.0.post0
1.2
1.3
1.3.post0
1.3.post1
1.4
1.4.1
1.4.1.post0
1.4.1.post1
1.5.0
1.5.0.post0
1.6.0
1.7.0
1.7.1
1.7.2
1.7.3
1.8.0
1.8.1
1.8.2
1.8.2.post0
1.8.2.post1
1.9.0
1.9.1
1.9.1.post0
1.9.2
1.9.2.post0
Fixed in
1.10.1
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2023-47115
GHSA-q68h-xwq5-mm7x
PYSEC-2024-126
Jan 24, 2024
Cross-site Scripting Vulnerability on Avatar Upload
7.1
/ 10
High
Network
Low
None
Required
Changed
Low
Low
Low
IntroductionThis write-up describes a vulnerability found in Label Studio, a popular open source data labeling tool. The vulnerability affects all versions of Label Studio prior to OverviewLabel Studio has a cross-site scripting (XSS) vulnerability that could be exploited when an authenticated user uploads a crafted image file for their avatar that gets rendered as a HTML file on the website. DescriptionThe following code snippet in Label Studio shows that the only verification check is that the file is an image by extracting the dimensions from the file.
Label Studio serves avatar images using Django's built-in
The issue with the Django Proof of ConceptBelow are the steps to reproduce this issue and execute JavaScript code in the context of the Label Studio website.
ImpactExecuting arbitrary JavaScript could result in an attacker performing malicious actions on Label Studio users if they visit the crafted avatar image. For an example, an attacker can craft a JavaScript payload that adds a new Django Super Administrator user if a Django administrator visits the image. Remediation Advice
Discovered
Affected versions
0.4.1
0.4.2
0.4.3
0.4.4
0.4.4.post1
0.4.4.post2
0.4.5
0.4.6
0.4.6.post1
0.4.6.post2
0.4.7
0.4.8
+ 62 more Show less
0.5.0
0.5.1
0.6.0
0.6.1
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.4.post0
0.7.4.post1
0.7.5.post1
0.7.5.post2
0.8.0
0.8.0.post0
0.8.1
0.8.1.post0
0.8.2
0.8.2.post0
0.9.0
0.9.0.post2
0.9.0.post3
0.9.0.post4
0.9.0.post5
0.9.1
0.9.1.post0
0.9.1.post1
0.9.1.post2
1.0.0
1.0.0.post0
1.0.0.post1
1.0.0.post2
1.0.0.post3
1.0.1
1.0.2
1.0.2.post0
1.1.0
1.1.0rc0
1.1.1
1.2
1.3
1.3.post0
1.3.post1
1.4
1.4.1
1.4.1.post0
1.4.1.post1
1.5.0
1.5.0.post0
1.6.0
1.7.0
1.7.1
1.7.2
1.7.3
1.8.0
1.8.1
1.8.2
1.8.2.post0
1.8.2.post1
1.9.0
1.9.1
1.9.1.post0
Fixed in
1.9.2
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2023-47117
GHSA-6hjj-gq77-j4qw
PYSEC-2023-275
Nov 14, 2023
Label Studio Object Relational Mapper Leak Vulnerability in Filtering Task
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
IntroductionThis write-up describes a vulnerability found in Label Studio, a popular open source data labeling tool. The vulnerability affects all versions of Label Studio prior to OverviewIn all current versions of Label Studio, the application allows users to insecurely set filters for filtering tasks. An attacker can construct a filter chain to filter tasks based on sensitive fields for all user accounts on the platform by exploiting Django's Object Relational Mapper (ORM). Since the results of query can be manipulated by the ORM filter, an attacker can leak these sensitive fields character by character. For an example, the following filter chain will task results by the password hash of an account on Label Studio.
For consistency, this type of vulnerability will be termed as ORM Leak in the rest of this disclosure. In addition, Label Studio had a hard coded secret key that an attacker can use to forge a session token of any user by exploiting this ORM Leak vulnerability to leak account password hashes. DescriptionThe following code snippet from the
These
The
The following code snippet of the
Finally, the
Proof of ConceptBelow are the steps to exploit about how to exploit this vulnerability to leak the password hash of an account on Label Studio.
The following example GIF demonstrates exploiting this ORM Leak vulnerability to retrieve the password hash
ImpactThis vulnerability can be exploited to completely compromise the confidentiality of highly sensitive account information, such as account password hashes. For all versions Remediation Advice
Discovered
| ||
1.5.0.post0
pre
12 CVEs
CVE-2026-22033
PYSEC-2026-1502
GHSA-2mq9-hm29-8qch
Jul 07, 2026
Label Studio is vulnerable to full account takeover by chaining Stored XSS + IDOR in User Profile via custom_hotkeys field
Critical
Network
Low
Low
None
PrologueThese vulnerabilities have been found and chained by DCODX-AI. Validation of the exploit chain has been confirmed manually. SummaryA persistent stored cross-site scripting (XSS) vulnerability exists in the custom_hotkeys functionality of the application. An authenticated attacker (or one who can trick a user/administrator into updating their custom_hotkeys) can inject JavaScript code that executes in other users’ browsers when those users load any page using the DetailsWithin
Here, user.custom_hotkeys is run through json_dumps_ensure_ascii (in In
The serializer allows
When another user loads a page using templates/base.html (for example PoC
Example request
Example response
ImpactExploitation impact:
Who is impacted:
Affected versions
0.4.1
0.4.2
0.4.3
0.4.4
0.4.4.post1
0.4.4.post2
0.4.5
0.4.6
0.4.6.post1
0.4.6.post2
0.4.7
0.4.8
+ 83 more Show less
0.5.0
0.5.1
0.6.0
0.6.1
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.4.post0
0.7.4.post1
0.7.5.post1
0.7.5.post2
0.8.0
0.8.0.post0
0.8.1
0.8.1.post0
0.8.2
0.8.2.post0
0.9.0
0.9.0.post2
0.9.0.post3
0.9.0.post4
0.9.0.post5
0.9.1
0.9.1.post0
0.9.1.post1
0.9.1.post2
1.0.0
1.0.0.post0
1.0.0.post1
1.0.0.post2
1.0.0.post3
1.0.1
1.0.2
1.0.2.post0
1.1.0
1.1.0rc0
1.1.1
1.10.0
1.10.0.post0
1.10.1
1.11.0
1.12.0
1.12.0.post0
1.12.1
1.13.0
1.13.1
1.14.0
1.14.0.post0
1.15.0
1.16.0
1.17.0
1.18.0
1.19.0
1.2
1.20.0
1.21.0
1.22.0
1.3
1.3.post0
1.3.post1
1.4
1.4.1
1.4.1.post0
1.4.1.post1
1.5.0
1.5.0.post0
1.6.0
1.7.0
1.7.1
1.7.2
1.7.3
1.8.0
1.8.1
1.8.2
1.8.2.post0
1.8.2.post1
1.9.0
1.9.1
1.9.1.post0
1.9.2
1.9.2.post0
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-25297
PYSEC-2026-1503
GHSA-m238-fmcw-wh58
Jul 07, 2026
Label Studio allows Server-Side Request Forgery in the S3 Storage Endpoint
8.6
/ 10
High
Network
Low
None
None
Changed
High
None
None
DescriptionLabel Studio's S3 storage integration feature contains a Server-Side Request Forgery (SSRF) vulnerability in its endpoint configuration. When creating an S3 storage connection, the application allows users to specify a custom S3 endpoint URL via the s3_endpoint parameter. This endpoint URL is passed directly to the boto3 AWS SDK without proper validation or restrictions on the protocol or destination. The vulnerability allows an attacker to make the application send HTTP requests to arbitrary internal services by specifying them as the S3 endpoint. When the storage sync operation is triggered, the application attempts to make S3 API calls to the specified endpoint, effectively making HTTP requests to the target service and returning the response in error messages. This SSRF vulnerability enables attackers to bypass network segmentation and access internal services that should not be accessible from the external network. The vulnerability is particularly severe because error messages from failed requests contain the full response body, allowing data exfiltration from internal services. Steps to reproduce
The application will attempt to connect to the specified endpoint URL as if it were an S3 service. When the request fails due to invalid S3 API responses, the error message will contain the raw response from the internal service, allowing access to internal resources. Mitigations
ImpactThis vulnerability has high severity as it allows authenticated users to make requests to arbitrary internal services from the application server, potentially exposing sensitive internal resources and bypassing network segmentation. The inclusion of response data in error messages makes this particularly effective for data exfiltration. Affected versions
0.4.1
0.4.2
0.4.3
0.4.4
0.4.4.post1
0.4.4.post2
0.4.5
0.4.6
0.4.6.post1
0.4.6.post2
0.4.7
0.4.8
+ 76 more Show less
0.5.0
0.5.1
0.6.0
0.6.1
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.4.post0
0.7.4.post1
0.7.5.post1
0.7.5.post2
0.8.0
0.8.0.post0
0.8.1
0.8.1.post0
0.8.2
0.8.2.post0
0.9.0
0.9.0.post2
0.9.0.post3
0.9.0.post4
0.9.0.post5
0.9.1
0.9.1.post0
0.9.1.post1
0.9.1.post2
1.0.0
1.0.0.post0
1.0.0.post1
1.0.0.post2
1.0.0.post3
1.0.1
1.0.2
1.0.2.post0
1.1.0
1.1.0rc0
1.1.1
1.10.0
1.10.0.post0
1.10.1
1.11.0
1.12.0
1.12.0.post0
1.12.1
1.13.0
1.13.1
1.14.0
1.14.0.post0
1.15.0
1.2
1.3
1.3.post0
1.3.post1
1.4
1.4.1
1.4.1.post0
1.4.1.post1
1.5.0
1.5.0.post0
1.6.0
1.7.0
1.7.1
1.7.2
1.7.3
1.8.0
1.8.1
1.8.2
1.8.2.post0
1.8.2.post1
1.9.0
1.9.1
1.9.1.post0
1.9.2
1.9.2.post0
Fixed in
1.16.0
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-25296
PYSEC-2026-1504
GHSA-wpq5-3366-mqw4
Jul 07, 2026
Label Studio allows Cross-Site Scripting (XSS) via GET request to `/projects/upload-example` endpoint
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
DescriptionLabel Studio's The vulnerability exists because the upload-example endpoint renders user-provided HTML content without proper sanitization on a GET request. This allows attackers to inject and execute arbitrary JavaScript in victims' browsers by getting them to visit a maliciously crafted URL. This is considered vulnerable because it enables attackers to execute JavaScript in victims' contexts, potentially allowing theft of sensitive data, session hijacking, or other malicious actions. Steps to reproduce
When executed, the payload causes the application to render an HTML page containing an img tag that fails to load, triggering the onerror event handler which executes base64-decoded JavaScript, demonstrating successful XSS execution in the victim's browser. Mitigations
ImpactThe vulnerability requires no special privileges and can be exploited by getting a victim to visit a crafted URL. The impact is high as it allows arbitrary JavaScript execution in victims' browsers, potentially exposing sensitive data or enabling account takeover through session theft. Affected versions
0.4.1
0.4.2
0.4.3
0.4.4
0.4.4.post1
0.4.4.post2
0.4.5
0.4.6
0.4.6.post1
0.4.6.post2
0.4.7
0.4.8
+ 76 more Show less
0.5.0
0.5.1
0.6.0
0.6.1
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.4.post0
0.7.4.post1
0.7.5.post1
0.7.5.post2
0.8.0
0.8.0.post0
0.8.1
0.8.1.post0
0.8.2
0.8.2.post0
0.9.0
0.9.0.post2
0.9.0.post3
0.9.0.post4
0.9.0.post5
0.9.1
0.9.1.post0
0.9.1.post1
0.9.1.post2
1.0.0
1.0.0.post0
1.0.0.post1
1.0.0.post2
1.0.0.post3
1.0.1
1.0.2
1.0.2.post0
1.1.0
1.1.0rc0
1.1.1
1.10.0
1.10.0.post0
1.10.1
1.11.0
1.12.0
1.12.0.post0
1.12.1
1.13.0
1.13.1
1.14.0
1.14.0.post0
1.15.0
1.2
1.3
1.3.post0
1.3.post1
1.4
1.4.1
1.4.1.post0
1.4.1.post1
1.5.0
1.5.0.post0
1.6.0
1.7.0
1.7.1
1.7.2
1.7.3
1.8.0
1.8.1
1.8.2
1.8.2.post0
1.8.2.post1
1.9.0
1.9.1
1.9.1.post0
1.9.2
1.9.2.post0
Fixed in
1.16.0
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-47783
GHSA-8jhr-wpcm-hh4h
PYSEC-2025-124
May 15, 2025
label-studio vulnerable to Cross-Site Scripting (Reflected) via the label_config parameter.
High
Network
Low
None
SummaryThe vulnerability allows an attacker to inject a malicious script into the context of a web page, which can lead to data theft, unauthorized actions on behalf of the user, and other attacks. DetailsThe vulnerability is reproducible when sending a properly formatted request to the
The vulnerability is specifically located in line 57, where HttpResponse is used.
PoCSend the following request after changing the
Or you can create a vulnerable HTML page by changing
Impact
Affected versions
0.4.1
0.4.2
0.4.3
0.4.4
0.4.4.post1
0.4.4.post2
0.4.5
0.4.6
0.4.6.post1
0.4.6.post2
0.4.7
0.4.8
+ 78 more Show less
0.5.0
0.5.1
0.6.0
0.6.1
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.4.post0
0.7.4.post1
0.7.5.post1
0.7.5.post2
0.8.0
0.8.0.post0
0.8.1
0.8.1.post0
0.8.2
0.8.2.post0
0.9.0
0.9.0.post2
0.9.0.post3
0.9.0.post4
0.9.0.post5
0.9.1
0.9.1.post0
0.9.1.post1
0.9.1.post2
1.0.0
1.0.0.post0
1.0.0.post1
1.0.0.post2
1.0.0.post3
1.0.1
1.0.2
1.0.2.post0
1.1.0
1.1.0rc0
1.1.1
1.10.0
1.10.0.post0
1.10.1
1.11.0
1.12.0
1.12.0.post0
1.12.1
1.13.0
1.13.1
1.14.0
1.14.0.post0
1.15.0
1.16.0
1.17.0
1.2
1.3
1.3.post0
1.3.post1
1.4
1.4.1
1.4.1.post0
1.4.1.post1
1.5.0
1.5.0.post0
1.6.0
1.7.0
1.7.1
1.7.2
1.7.3
1.8.0
1.8.1
1.8.2
1.8.2.post0
1.8.2.post1
1.9.0
1.9.1
1.9.1.post0
1.9.2
1.9.2.post0
Fixed in
1.18.0
References
Updated Jun 06, 2026 · Source: OSV.dev
CVE-2024-26152
PYSEC-2024-249
GHSA-6xv9-957j-qfhg
Feb 22, 2024
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
SummaryOn all Label Studio versions prior to 1.11.0, data imported via file upload feature is not properly sanitized prior to being rendered within a DetailsNeed permission to use the "data import" function. This was reproduced on Label Studio 1.10.1. PoC
The following are the contents of the files used in the PoC
ImpactMalicious scripts can be injected into the code, and when linked with vulnerabilities such as CSRF, it can cause even greater damage. In particular, It can become a source of further attacks, especially when linked to social engineering. Affected versions
0.4.1
0.4.2
0.4.3
0.4.4
0.4.4.post1
0.4.4.post2
0.4.5
0.4.6
0.4.6.post1
0.4.6.post2
0.4.7
0.4.8
+ 113 more Show less
0.5.0
0.5.1
0.6.0
0.6.1
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.4.post0
0.7.4.post1
0.7.5.post1
0.7.5.post2
0.8.0
0.8.0.post0
0.8.1
0.8.1.post0
0.8.2
0.8.2.post0
0.9.0
0.9.0.post2
0.9.0.post3
0.9.0.post4
0.9.0.post5
0.9.1
0.9.1.post0
0.9.1.post1
0.9.1.post2
1.0.0
1.0.0.post0
1.0.0.post1
1.0.0.post2
1.0.0.post3
1.0.1
1.0.2
1.0.2.post0
1.1.0
1.1.0rc0
1.1.1
1.10.0
1.10.0.post0
1.10.1
1.2
1.3
1.3.post0
1.3.post1
1.4
1.4.1
1.4.1.post0
1.4.1.post1
1.5.0
1.5.0.post0
1.6.0
1.7.0
1.7.1
1.7.2
1.7.3
1.8.0
1.8.1
1.8.2
1.8.2.post0
1.8.2.post1
1.9.0
1.9.1
1.9.1.post0
1.9.2
1.9.2.post0
v1.4.1
v1.4.0
v1.3.0
v1.2.0
v1.1.1
v1.1.0
v1.0.2
v1.0.1
v1.0.0
v0.9.1.post1
v0.9.1.post0
v0.9.0.post5
v0.9.0.post4
v0.9.0.post3
v0.9.0
v0.8.2
v0.8.1
v0.8.0
v0.7.5.post0
v0.7.3
v0.7.2
v0.7.1
v0.7.0
v0.6.1
v0.6.0
v0.5.1
v0.4.8
v0.4.7
v0.4.6
v0.4.5
v0.4.4
v0.4.0
v0.3.0
v0.2.2
v.0.2.1-8
v.0.2.1-5
v.0.2.1-4
v.0.2.1-3
v.0.2.1-2
v.0.2.0
v.0.1.6
v.0.1.5
v.0.1.4
v.0.1.2
v.0.1.1
v.0.1.0
Fixed in
1.11.0
References
Updated Jun 10, 2026 · Source: OSV.dev
CVE-2023-47116
GHSA-p59w-9gqw-wj8r
PYSEC-2024-127
Jan 31, 2024
Label Studio SSRF on Import Bypassing `SSRF_PROTECTION_ENABLED` Protections
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
IntroductionThis write-up describes a vulnerability found in Label Studio, a popular open source data labeling tool. The vulnerability affects all versions of Label Studio prior to OverviewLabel Studio's SSRF protections that can be enabled by setting the DescriptionThe following
The
The issue here is the SSRF validation is only performed before the request is sent, and does not validate the destination IP address. Therefore, an attacker can either redirect the request or perform a DNS rebinding attack to bypass this protection. Proof of ConceptBoth the HTTP redirection and DNS rebinding methods for bypassing Label Studio's SSRF protections are explained below. HTTP RedirectionThe python
DNS Rebinding AttackDNS rebinding can bypass SSRF protections by resolving to an external IP address for the first resolution, but when the request is sent resolves to an internal IP address that is blocked. For an example, the domain ImpactSSRF vulnerabilities pose a significant risk on cloud environments, since instance credentials are managed by internal web APIs. An attacker can bypass Label Studio's SSRF protections to access internal web servers and partially compromise the confidentiality of those internal servers. Remediation Advice
Discovered
Affected versions
0.4.1
0.4.2
0.4.3
0.4.4
0.4.4.post1
0.4.4.post2
0.4.5
0.4.6
0.4.6.post1
0.4.6.post2
0.4.7
0.4.8
+ 67 more Show less
0.5.0
0.5.1
0.6.0
0.6.1
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.4.post0
0.7.4.post1
0.7.5.post1
0.7.5.post2
0.8.0
0.8.0.post0
0.8.1
0.8.1.post0
0.8.2
0.8.2.post0
0.9.0
0.9.0.post2
0.9.0.post3
0.9.0.post4
0.9.0.post5
0.9.1
0.9.1.post0
0.9.1.post1
0.9.1.post2
1.0.0
1.0.0.post0
1.0.0.post1
1.0.0.post2
1.0.0.post3
1.0.1
1.0.2
1.0.2.post0
1.1.0
1.1.0rc0
1.1.1
1.10.0
1.10.0.post0
1.10.1
1.2
1.3
1.3.post0
1.3.post1
1.4
1.4.1
1.4.1.post0
1.4.1.post1
1.5.0
1.5.0.post0
1.6.0
1.7.0
1.7.1
1.7.2
1.7.3
1.8.0
1.8.1
1.8.2
1.8.2.post0
1.8.2.post1
1.9.0
1.9.1
1.9.1.post0
1.9.2
1.9.2.post0
Fixed in
1.11.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-23633
GHSA-fq23-g58m-799r
PYSEC-2024-128
Jan 24, 2024
Cross-site Scripting Vulnerability on Data Import
4.7
/ 10
Medium
Network
Low
None
Required
Changed
Low
None
None
IntroductionThis write-up describes a vulnerability found in Label Studio, a popular open source data labeling tool. The vulnerability affects all versions of Label Studio prior to OverviewLabel Studio had a remote import feature allowed users to import data from a remote web source, that was downloaded and could be viewed on the website. This feature could had been abused to download a HTML file that executed malicious JavaScript code in the context of the Label Studio website. DescriptionThe following code snippet in Label Studio showed that is a URL passed the SSRF verification checks, the contents of the file would be downloaded using the filename in the URL.
The downloaded file path could then be retrieved by sending a request to
Since the Proof of ConceptBelow were the steps to recreate this issue:
ImpactExecuting arbitrary JavaScript could result in an attacker performing malicious actions on Label Studio users if they visit the crafted avatar image. For an example, an attacker can craft a JavaScript payload that adds a new Django Super Administrator user if a Django administrator visits the image. Remediation Advice
Discovered
Affected versions
0.4.1
0.4.2
0.4.3
0.4.4
0.4.4.post1
0.4.4.post2
0.4.5
0.4.6
0.4.6.post1
0.4.6.post2
0.4.7
0.4.8
+ 66 more Show less
0.5.0
0.5.1
0.6.0
0.6.1
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.4.post0
0.7.4.post1
0.7.5.post1
0.7.5.post2
0.8.0
0.8.0.post0
0.8.1
0.8.1.post0
0.8.2
0.8.2.post0
0.9.0
0.9.0.post2
0.9.0.post3
0.9.0.post4
0.9.0.post5
0.9.1
0.9.1.post0
0.9.1.post1
0.9.1.post2
1.0.0
1.0.0.post0
1.0.0.post1
1.0.0.post2
1.0.0.post3
1.0.1
1.0.2
1.0.2.post0
1.1.0
1.1.0rc0
1.1.1
1.10.0
1.10.0.post0
1.2
1.3
1.3.post0
1.3.post1
1.4
1.4.1
1.4.1.post0
1.4.1.post1
1.5.0
1.5.0.post0
1.6.0
1.7.0
1.7.1
1.7.2
1.7.3
1.8.0
1.8.1
1.8.2
1.8.2.post0
1.8.2.post1
1.9.0
1.9.1
1.9.1.post0
1.9.2
1.9.2.post0
Fixed in
1.10.1
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2023-47115
GHSA-q68h-xwq5-mm7x
PYSEC-2024-126
Jan 24, 2024
Cross-site Scripting Vulnerability on Avatar Upload
7.1
/ 10
High
Network
Low
None
Required
Changed
Low
Low
Low
IntroductionThis write-up describes a vulnerability found in Label Studio, a popular open source data labeling tool. The vulnerability affects all versions of Label Studio prior to OverviewLabel Studio has a cross-site scripting (XSS) vulnerability that could be exploited when an authenticated user uploads a crafted image file for their avatar that gets rendered as a HTML file on the website. DescriptionThe following code snippet in Label Studio shows that the only verification check is that the file is an image by extracting the dimensions from the file.
Label Studio serves avatar images using Django's built-in
The issue with the Django Proof of ConceptBelow are the steps to reproduce this issue and execute JavaScript code in the context of the Label Studio website.
ImpactExecuting arbitrary JavaScript could result in an attacker performing malicious actions on Label Studio users if they visit the crafted avatar image. For an example, an attacker can craft a JavaScript payload that adds a new Django Super Administrator user if a Django administrator visits the image. Remediation Advice
Discovered
Affected versions
0.4.1
0.4.2
0.4.3
0.4.4
0.4.4.post1
0.4.4.post2
0.4.5
0.4.6
0.4.6.post1
0.4.6.post2
0.4.7
0.4.8
+ 62 more Show less
0.5.0
0.5.1
0.6.0
0.6.1
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.4.post0
0.7.4.post1
0.7.5.post1
0.7.5.post2
0.8.0
0.8.0.post0
0.8.1
0.8.1.post0
0.8.2
0.8.2.post0
0.9.0
0.9.0.post2
0.9.0.post3
0.9.0.post4
0.9.0.post5
0.9.1
0.9.1.post0
0.9.1.post1
0.9.1.post2
1.0.0
1.0.0.post0
1.0.0.post1
1.0.0.post2
1.0.0.post3
1.0.1
1.0.2
1.0.2.post0
1.1.0
1.1.0rc0
1.1.1
1.2
1.3
1.3.post0
1.3.post1
1.4
1.4.1
1.4.1.post0
1.4.1.post1
1.5.0
1.5.0.post0
1.6.0
1.7.0
1.7.1
1.7.2
1.7.3
1.8.0
1.8.1
1.8.2
1.8.2.post0
1.8.2.post1
1.9.0
1.9.1
1.9.1.post0
Fixed in
1.9.2
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2023-47117
GHSA-6hjj-gq77-j4qw
PYSEC-2023-275
Nov 14, 2023
Label Studio Object Relational Mapper Leak Vulnerability in Filtering Task
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
IntroductionThis write-up describes a vulnerability found in Label Studio, a popular open source data labeling tool. The vulnerability affects all versions of Label Studio prior to OverviewIn all current versions of Label Studio, the application allows users to insecurely set filters for filtering tasks. An attacker can construct a filter chain to filter tasks based on sensitive fields for all user accounts on the platform by exploiting Django's Object Relational Mapper (ORM). Since the results of query can be manipulated by the ORM filter, an attacker can leak these sensitive fields character by character. For an example, the following filter chain will task results by the password hash of an account on Label Studio.
For consistency, this type of vulnerability will be termed as ORM Leak in the rest of this disclosure. In addition, Label Studio had a hard coded secret key that an attacker can use to forge a session token of any user by exploiting this ORM Leak vulnerability to leak account password hashes. DescriptionThe following code snippet from the
These
The
The following code snippet of the
Finally, the
Proof of ConceptBelow are the steps to exploit about how to exploit this vulnerability to leak the password hash of an account on Label Studio.
The following example GIF demonstrates exploiting this ORM Leak vulnerability to retrieve the password hash
ImpactThis vulnerability can be exploited to completely compromise the confidentiality of highly sensitive account information, such as account password hashes. For all versions Remediation Advice
Discovered
| ||
1.5.0
minor
12 CVEs
CVE-2026-22033
PYSEC-2026-1502
GHSA-2mq9-hm29-8qch
Jul 07, 2026
Label Studio is vulnerable to full account takeover by chaining Stored XSS + IDOR in User Profile via custom_hotkeys field
Critical
Network
Low
Low
None
PrologueThese vulnerabilities have been found and chained by DCODX-AI. Validation of the exploit chain has been confirmed manually. SummaryA persistent stored cross-site scripting (XSS) vulnerability exists in the custom_hotkeys functionality of the application. An authenticated attacker (or one who can trick a user/administrator into updating their custom_hotkeys) can inject JavaScript code that executes in other users’ browsers when those users load any page using the DetailsWithin
Here, user.custom_hotkeys is run through json_dumps_ensure_ascii (in In
The serializer allows
When another user loads a page using templates/base.html (for example PoC
Example request
Example response
ImpactExploitation impact:
Who is impacted:
Affected versions
0.4.1
0.4.2
0.4.3
0.4.4
0.4.4.post1
0.4.4.post2
0.4.5
0.4.6
0.4.6.post1
0.4.6.post2
0.4.7
0.4.8
+ 83 more Show less
0.5.0
0.5.1
0.6.0
0.6.1
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.4.post0
0.7.4.post1
0.7.5.post1
0.7.5.post2
0.8.0
0.8.0.post0
0.8.1
0.8.1.post0
0.8.2
0.8.2.post0
0.9.0
0.9.0.post2
0.9.0.post3
0.9.0.post4
0.9.0.post5
0.9.1
0.9.1.post0
0.9.1.post1
0.9.1.post2
1.0.0
1.0.0.post0
1.0.0.post1
1.0.0.post2
1.0.0.post3
1.0.1
1.0.2
1.0.2.post0
1.1.0
1.1.0rc0
1.1.1
1.10.0
1.10.0.post0
1.10.1
1.11.0
1.12.0
1.12.0.post0
1.12.1
1.13.0
1.13.1
1.14.0
1.14.0.post0
1.15.0
1.16.0
1.17.0
1.18.0
1.19.0
1.2
1.20.0
1.21.0
1.22.0
1.3
1.3.post0
1.3.post1
1.4
1.4.1
1.4.1.post0
1.4.1.post1
1.5.0
1.5.0.post0
1.6.0
1.7.0
1.7.1
1.7.2
1.7.3
1.8.0
1.8.1
1.8.2
1.8.2.post0
1.8.2.post1
1.9.0
1.9.1
1.9.1.post0
1.9.2
1.9.2.post0
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-25297
PYSEC-2026-1503
GHSA-m238-fmcw-wh58
Jul 07, 2026
Label Studio allows Server-Side Request Forgery in the S3 Storage Endpoint
8.6
/ 10
High
Network
Low
None
None
Changed
High
None
None
DescriptionLabel Studio's S3 storage integration feature contains a Server-Side Request Forgery (SSRF) vulnerability in its endpoint configuration. When creating an S3 storage connection, the application allows users to specify a custom S3 endpoint URL via the s3_endpoint parameter. This endpoint URL is passed directly to the boto3 AWS SDK without proper validation or restrictions on the protocol or destination. The vulnerability allows an attacker to make the application send HTTP requests to arbitrary internal services by specifying them as the S3 endpoint. When the storage sync operation is triggered, the application attempts to make S3 API calls to the specified endpoint, effectively making HTTP requests to the target service and returning the response in error messages. This SSRF vulnerability enables attackers to bypass network segmentation and access internal services that should not be accessible from the external network. The vulnerability is particularly severe because error messages from failed requests contain the full response body, allowing data exfiltration from internal services. Steps to reproduce
The application will attempt to connect to the specified endpoint URL as if it were an S3 service. When the request fails due to invalid S3 API responses, the error message will contain the raw response from the internal service, allowing access to internal resources. Mitigations
ImpactThis vulnerability has high severity as it allows authenticated users to make requests to arbitrary internal services from the application server, potentially exposing sensitive internal resources and bypassing network segmentation. The inclusion of response data in error messages makes this particularly effective for data exfiltration. Affected versions
0.4.1
0.4.2
0.4.3
0.4.4
0.4.4.post1
0.4.4.post2
0.4.5
0.4.6
0.4.6.post1
0.4.6.post2
0.4.7
0.4.8
+ 76 more Show less
0.5.0
0.5.1
0.6.0
0.6.1
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.4.post0
0.7.4.post1
0.7.5.post1
0.7.5.post2
0.8.0
0.8.0.post0
0.8.1
0.8.1.post0
0.8.2
0.8.2.post0
0.9.0
0.9.0.post2
0.9.0.post3
0.9.0.post4
0.9.0.post5
0.9.1
0.9.1.post0
0.9.1.post1
0.9.1.post2
1.0.0
1.0.0.post0
1.0.0.post1
1.0.0.post2
1.0.0.post3
1.0.1
1.0.2
1.0.2.post0
1.1.0
1.1.0rc0
1.1.1
1.10.0
1.10.0.post0
1.10.1
1.11.0
1.12.0
1.12.0.post0
1.12.1
1.13.0
1.13.1
1.14.0
1.14.0.post0
1.15.0
1.2
1.3
1.3.post0
1.3.post1
1.4
1.4.1
1.4.1.post0
1.4.1.post1
1.5.0
1.5.0.post0
1.6.0
1.7.0
1.7.1
1.7.2
1.7.3
1.8.0
1.8.1
1.8.2
1.8.2.post0
1.8.2.post1
1.9.0
1.9.1
1.9.1.post0
1.9.2
1.9.2.post0
Fixed in
1.16.0
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-25296
PYSEC-2026-1504
GHSA-wpq5-3366-mqw4
Jul 07, 2026
Label Studio allows Cross-Site Scripting (XSS) via GET request to `/projects/upload-example` endpoint
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
DescriptionLabel Studio's The vulnerability exists because the upload-example endpoint renders user-provided HTML content without proper sanitization on a GET request. This allows attackers to inject and execute arbitrary JavaScript in victims' browsers by getting them to visit a maliciously crafted URL. This is considered vulnerable because it enables attackers to execute JavaScript in victims' contexts, potentially allowing theft of sensitive data, session hijacking, or other malicious actions. Steps to reproduce
When executed, the payload causes the application to render an HTML page containing an img tag that fails to load, triggering the onerror event handler which executes base64-decoded JavaScript, demonstrating successful XSS execution in the victim's browser. Mitigations
ImpactThe vulnerability requires no special privileges and can be exploited by getting a victim to visit a crafted URL. The impact is high as it allows arbitrary JavaScript execution in victims' browsers, potentially exposing sensitive data or enabling account takeover through session theft. Affected versions
0.4.1
0.4.2
0.4.3
0.4.4
0.4.4.post1
0.4.4.post2
0.4.5
0.4.6
0.4.6.post1
0.4.6.post2
0.4.7
0.4.8
+ 76 more Show less
0.5.0
0.5.1
0.6.0
0.6.1
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.4.post0
0.7.4.post1
0.7.5.post1
0.7.5.post2
0.8.0
0.8.0.post0
0.8.1
0.8.1.post0
0.8.2
0.8.2.post0
0.9.0
0.9.0.post2
0.9.0.post3
0.9.0.post4
0.9.0.post5
0.9.1
0.9.1.post0
0.9.1.post1
0.9.1.post2
1.0.0
1.0.0.post0
1.0.0.post1
1.0.0.post2
1.0.0.post3
1.0.1
1.0.2
1.0.2.post0
1.1.0
1.1.0rc0
1.1.1
1.10.0
1.10.0.post0
1.10.1
1.11.0
1.12.0
1.12.0.post0
1.12.1
1.13.0
1.13.1
1.14.0
1.14.0.post0
1.15.0
1.2
1.3
1.3.post0
1.3.post1
1.4
1.4.1
1.4.1.post0
1.4.1.post1
1.5.0
1.5.0.post0
1.6.0
1.7.0
1.7.1
1.7.2
1.7.3
1.8.0
1.8.1
1.8.2
1.8.2.post0
1.8.2.post1
1.9.0
1.9.1
1.9.1.post0
1.9.2
1.9.2.post0
Fixed in
1.16.0
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-47783
GHSA-8jhr-wpcm-hh4h
PYSEC-2025-124
May 15, 2025
label-studio vulnerable to Cross-Site Scripting (Reflected) via the label_config parameter.
High
Network
Low
None
SummaryThe vulnerability allows an attacker to inject a malicious script into the context of a web page, which can lead to data theft, unauthorized actions on behalf of the user, and other attacks. DetailsThe vulnerability is reproducible when sending a properly formatted request to the
The vulnerability is specifically located in line 57, where HttpResponse is used.
PoCSend the following request after changing the
Or you can create a vulnerable HTML page by changing
Impact
Affected versions
0.4.1
0.4.2
0.4.3
0.4.4
0.4.4.post1
0.4.4.post2
0.4.5
0.4.6
0.4.6.post1
0.4.6.post2
0.4.7
0.4.8
+ 78 more Show less
0.5.0
0.5.1
0.6.0
0.6.1
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.4.post0
0.7.4.post1
0.7.5.post1
0.7.5.post2
0.8.0
0.8.0.post0
0.8.1
0.8.1.post0
0.8.2
0.8.2.post0
0.9.0
0.9.0.post2
0.9.0.post3
0.9.0.post4
0.9.0.post5
0.9.1
0.9.1.post0
0.9.1.post1
0.9.1.post2
1.0.0
1.0.0.post0
1.0.0.post1
1.0.0.post2
1.0.0.post3
1.0.1
1.0.2
1.0.2.post0
1.1.0
1.1.0rc0
1.1.1
1.10.0
1.10.0.post0
1.10.1
1.11.0
1.12.0
1.12.0.post0
1.12.1
1.13.0
1.13.1
1.14.0
1.14.0.post0
1.15.0
1.16.0
1.17.0
1.2
1.3
1.3.post0
1.3.post1
1.4
1.4.1
1.4.1.post0
1.4.1.post1
1.5.0
1.5.0.post0
1.6.0
1.7.0
1.7.1
1.7.2
1.7.3
1.8.0
1.8.1
1.8.2
1.8.2.post0
1.8.2.post1
1.9.0
1.9.1
1.9.1.post0
1.9.2
1.9.2.post0
Fixed in
1.18.0
References
Updated Jun 06, 2026 · Source: OSV.dev
CVE-2024-26152
PYSEC-2024-249
GHSA-6xv9-957j-qfhg
Feb 22, 2024
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
SummaryOn all Label Studio versions prior to 1.11.0, data imported via file upload feature is not properly sanitized prior to being rendered within a DetailsNeed permission to use the "data import" function. This was reproduced on Label Studio 1.10.1. PoC
The following are the contents of the files used in the PoC
ImpactMalicious scripts can be injected into the code, and when linked with vulnerabilities such as CSRF, it can cause even greater damage. In particular, It can become a source of further attacks, especially when linked to social engineering. Affected versions
0.4.1
0.4.2
0.4.3
0.4.4
0.4.4.post1
0.4.4.post2
0.4.5
0.4.6
0.4.6.post1
0.4.6.post2
0.4.7
0.4.8
+ 113 more Show less
0.5.0
0.5.1
0.6.0
0.6.1
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.4.post0
0.7.4.post1
0.7.5.post1
0.7.5.post2
0.8.0
0.8.0.post0
0.8.1
0.8.1.post0
0.8.2
0.8.2.post0
0.9.0
0.9.0.post2
0.9.0.post3
0.9.0.post4
0.9.0.post5
0.9.1
0.9.1.post0
0.9.1.post1
0.9.1.post2
1.0.0
1.0.0.post0
1.0.0.post1
1.0.0.post2
1.0.0.post3
1.0.1
1.0.2
1.0.2.post0
1.1.0
1.1.0rc0
1.1.1
1.10.0
1.10.0.post0
1.10.1
1.2
1.3
1.3.post0
1.3.post1
1.4
1.4.1
1.4.1.post0
1.4.1.post1
1.5.0
1.5.0.post0
1.6.0
1.7.0
1.7.1
1.7.2
1.7.3
1.8.0
1.8.1
1.8.2
1.8.2.post0
1.8.2.post1
1.9.0
1.9.1
1.9.1.post0
1.9.2
1.9.2.post0
v1.4.1
v1.4.0
v1.3.0
v1.2.0
v1.1.1
v1.1.0
v1.0.2
v1.0.1
v1.0.0
v0.9.1.post1
v0.9.1.post0
v0.9.0.post5
v0.9.0.post4
v0.9.0.post3
v0.9.0
v0.8.2
v0.8.1
v0.8.0
v0.7.5.post0
v0.7.3
v0.7.2
v0.7.1
v0.7.0
v0.6.1
v0.6.0
v0.5.1
v0.4.8
v0.4.7
v0.4.6
v0.4.5
v0.4.4
v0.4.0
v0.3.0
v0.2.2
v.0.2.1-8
v.0.2.1-5
v.0.2.1-4
v.0.2.1-3
v.0.2.1-2
v.0.2.0
v.0.1.6
v.0.1.5
v.0.1.4
v.0.1.2
v.0.1.1
v.0.1.0
Fixed in
1.11.0
References
Updated Jun 10, 2026 · Source: OSV.dev
CVE-2023-47116
GHSA-p59w-9gqw-wj8r
PYSEC-2024-127
Jan 31, 2024
Label Studio SSRF on Import Bypassing `SSRF_PROTECTION_ENABLED` Protections
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
IntroductionThis write-up describes a vulnerability found in Label Studio, a popular open source data labeling tool. The vulnerability affects all versions of Label Studio prior to OverviewLabel Studio's SSRF protections that can be enabled by setting the DescriptionThe following
The
The issue here is the SSRF validation is only performed before the request is sent, and does not validate the destination IP address. Therefore, an attacker can either redirect the request or perform a DNS rebinding attack to bypass this protection. Proof of ConceptBoth the HTTP redirection and DNS rebinding methods for bypassing Label Studio's SSRF protections are explained below. HTTP RedirectionThe python
DNS Rebinding AttackDNS rebinding can bypass SSRF protections by resolving to an external IP address for the first resolution, but when the request is sent resolves to an internal IP address that is blocked. For an example, the domain ImpactSSRF vulnerabilities pose a significant risk on cloud environments, since instance credentials are managed by internal web APIs. An attacker can bypass Label Studio's SSRF protections to access internal web servers and partially compromise the confidentiality of those internal servers. Remediation Advice
Discovered
Affected versions
0.4.1
0.4.2
0.4.3
0.4.4
0.4.4.post1
0.4.4.post2
0.4.5
0.4.6
0.4.6.post1
0.4.6.post2
0.4.7
0.4.8
+ 67 more Show less
0.5.0
0.5.1
0.6.0
0.6.1
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.4.post0
0.7.4.post1
0.7.5.post1
0.7.5.post2
0.8.0
0.8.0.post0
0.8.1
0.8.1.post0
0.8.2
0.8.2.post0
0.9.0
0.9.0.post2
0.9.0.post3
0.9.0.post4
0.9.0.post5
0.9.1
0.9.1.post0
0.9.1.post1
0.9.1.post2
1.0.0
1.0.0.post0
1.0.0.post1
1.0.0.post2
1.0.0.post3
1.0.1
1.0.2
1.0.2.post0
1.1.0
1.1.0rc0
1.1.1
1.10.0
1.10.0.post0
1.10.1
1.2
1.3
1.3.post0
1.3.post1
1.4
1.4.1
1.4.1.post0
1.4.1.post1
1.5.0
1.5.0.post0
1.6.0
1.7.0
1.7.1
1.7.2
1.7.3
1.8.0
1.8.1
1.8.2
1.8.2.post0
1.8.2.post1
1.9.0
1.9.1
1.9.1.post0
1.9.2
1.9.2.post0
Fixed in
1.11.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-23633
GHSA-fq23-g58m-799r
PYSEC-2024-128
Jan 24, 2024
Cross-site Scripting Vulnerability on Data Import
4.7
/ 10
Medium
Network
Low
None
Required
Changed
Low
None
None
IntroductionThis write-up describes a vulnerability found in Label Studio, a popular open source data labeling tool. The vulnerability affects all versions of Label Studio prior to OverviewLabel Studio had a remote import feature allowed users to import data from a remote web source, that was downloaded and could be viewed on the website. This feature could had been abused to download a HTML file that executed malicious JavaScript code in the context of the Label Studio website. DescriptionThe following code snippet in Label Studio showed that is a URL passed the SSRF verification checks, the contents of the file would be downloaded using the filename in the URL.
The downloaded file path could then be retrieved by sending a request to
Since the Proof of ConceptBelow were the steps to recreate this issue:
ImpactExecuting arbitrary JavaScript could result in an attacker performing malicious actions on Label Studio users if they visit the crafted avatar image. For an example, an attacker can craft a JavaScript payload that adds a new Django Super Administrator user if a Django administrator visits the image. Remediation Advice
Discovered
Affected versions
0.4.1
0.4.2
0.4.3
0.4.4
0.4.4.post1
0.4.4.post2
0.4.5
0.4.6
0.4.6.post1
0.4.6.post2
0.4.7
0.4.8
+ 66 more Show less
0.5.0
0.5.1
0.6.0
0.6.1
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.4.post0
0.7.4.post1
0.7.5.post1
0.7.5.post2
0.8.0
0.8.0.post0
0.8.1
0.8.1.post0
0.8.2
0.8.2.post0
0.9.0
0.9.0.post2
0.9.0.post3
0.9.0.post4
0.9.0.post5
0.9.1
0.9.1.post0
0.9.1.post1
0.9.1.post2
1.0.0
1.0.0.post0
1.0.0.post1
1.0.0.post2
1.0.0.post3
1.0.1
1.0.2
1.0.2.post0
1.1.0
1.1.0rc0
1.1.1
1.10.0
1.10.0.post0
1.2
1.3
1.3.post0
1.3.post1
1.4
1.4.1
1.4.1.post0
1.4.1.post1
1.5.0
1.5.0.post0
1.6.0
1.7.0
1.7.1
1.7.2
1.7.3
1.8.0
1.8.1
1.8.2
1.8.2.post0
1.8.2.post1
1.9.0
1.9.1
1.9.1.post0
1.9.2
1.9.2.post0
Fixed in
1.10.1
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2023-47115
GHSA-q68h-xwq5-mm7x
PYSEC-2024-126
Jan 24, 2024
Cross-site Scripting Vulnerability on Avatar Upload
7.1
/ 10
High
Network
Low
None
Required
Changed
Low
Low
Low
IntroductionThis write-up describes a vulnerability found in Label Studio, a popular open source data labeling tool. The vulnerability affects all versions of Label Studio prior to OverviewLabel Studio has a cross-site scripting (XSS) vulnerability that could be exploited when an authenticated user uploads a crafted image file for their avatar that gets rendered as a HTML file on the website. DescriptionThe following code snippet in Label Studio shows that the only verification check is that the file is an image by extracting the dimensions from the file.
Label Studio serves avatar images using Django's built-in
The issue with the Django Proof of ConceptBelow are the steps to reproduce this issue and execute JavaScript code in the context of the Label Studio website.
ImpactExecuting arbitrary JavaScript could result in an attacker performing malicious actions on Label Studio users if they visit the crafted avatar image. For an example, an attacker can craft a JavaScript payload that adds a new Django Super Administrator user if a Django administrator visits the image. Remediation Advice
Discovered
Affected versions
0.4.1
0.4.2
0.4.3
0.4.4
0.4.4.post1
0.4.4.post2
0.4.5
0.4.6
0.4.6.post1
0.4.6.post2
0.4.7
0.4.8
+ 62 more Show less
0.5.0
0.5.1
0.6.0
0.6.1
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.4.post0
0.7.4.post1
0.7.5.post1
0.7.5.post2
0.8.0
0.8.0.post0
0.8.1
0.8.1.post0
0.8.2
0.8.2.post0
0.9.0
0.9.0.post2
0.9.0.post3
0.9.0.post4
0.9.0.post5
0.9.1
0.9.1.post0
0.9.1.post1
0.9.1.post2
1.0.0
1.0.0.post0
1.0.0.post1
1.0.0.post2
1.0.0.post3
1.0.1
1.0.2
1.0.2.post0
1.1.0
1.1.0rc0
1.1.1
1.2
1.3
1.3.post0
1.3.post1
1.4
1.4.1
1.4.1.post0
1.4.1.post1
1.5.0
1.5.0.post0
1.6.0
1.7.0
1.7.1
1.7.2
1.7.3
1.8.0
1.8.1
1.8.2
1.8.2.post0
1.8.2.post1
1.9.0
1.9.1
1.9.1.post0
Fixed in
1.9.2
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2023-47117
GHSA-6hjj-gq77-j4qw
PYSEC-2023-275
Nov 14, 2023
Label Studio Object Relational Mapper Leak Vulnerability in Filtering Task
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
IntroductionThis write-up describes a vulnerability found in Label Studio, a popular open source data labeling tool. The vulnerability affects all versions of Label Studio prior to OverviewIn all current versions of Label Studio, the application allows users to insecurely set filters for filtering tasks. An attacker can construct a filter chain to filter tasks based on sensitive fields for all user accounts on the platform by exploiting Django's Object Relational Mapper (ORM). Since the results of query can be manipulated by the ORM filter, an attacker can leak these sensitive fields character by character. For an example, the following filter chain will task results by the password hash of an account on Label Studio.
For consistency, this type of vulnerability will be termed as ORM Leak in the rest of this disclosure. In addition, Label Studio had a hard coded secret key that an attacker can use to forge a session token of any user by exploiting this ORM Leak vulnerability to leak account password hashes. DescriptionThe following code snippet from the
These
The
The following code snippet of the
Finally, the
Proof of ConceptBelow are the steps to exploit about how to exploit this vulnerability to leak the password hash of an account on Label Studio.
The following example GIF demonstrates exploiting this ORM Leak vulnerability to retrieve the password hash
ImpactThis vulnerability can be exploited to completely compromise the confidentiality of highly sensitive account information, such as account password hashes. For all versions Remediation Advice
Discovered
| ||
1.4.1.post1
pre
12 CVEs
CVE-2026-22033
PYSEC-2026-1502
GHSA-2mq9-hm29-8qch
Jul 07, 2026
Label Studio is vulnerable to full account takeover by chaining Stored XSS + IDOR in User Profile via custom_hotkeys field
Critical
Network
Low
Low
None
PrologueThese vulnerabilities have been found and chained by DCODX-AI. Validation of the exploit chain has been confirmed manually. SummaryA persistent stored cross-site scripting (XSS) vulnerability exists in the custom_hotkeys functionality of the application. An authenticated attacker (or one who can trick a user/administrator into updating their custom_hotkeys) can inject JavaScript code that executes in other users’ browsers when those users load any page using the DetailsWithin
Here, user.custom_hotkeys is run through json_dumps_ensure_ascii (in In
The serializer allows
When another user loads a page using templates/base.html (for example PoC
Example request
Example response
ImpactExploitation impact:
Who is impacted:
Affected versions
0.4.1
0.4.2
0.4.3
0.4.4
0.4.4.post1
0.4.4.post2
0.4.5
0.4.6
0.4.6.post1
0.4.6.post2
0.4.7
0.4.8
+ 83 more Show less
0.5.0
0.5.1
0.6.0
0.6.1
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.4.post0
0.7.4.post1
0.7.5.post1
0.7.5.post2
0.8.0
0.8.0.post0
0.8.1
0.8.1.post0
0.8.2
0.8.2.post0
0.9.0
0.9.0.post2
0.9.0.post3
0.9.0.post4
0.9.0.post5
0.9.1
0.9.1.post0
0.9.1.post1
0.9.1.post2
1.0.0
1.0.0.post0
1.0.0.post1
1.0.0.post2
1.0.0.post3
1.0.1
1.0.2
1.0.2.post0
1.1.0
1.1.0rc0
1.1.1
1.10.0
1.10.0.post0
1.10.1
1.11.0
1.12.0
1.12.0.post0
1.12.1
1.13.0
1.13.1
1.14.0
1.14.0.post0
1.15.0
1.16.0
1.17.0
1.18.0
1.19.0
1.2
1.20.0
1.21.0
1.22.0
1.3
1.3.post0
1.3.post1
1.4
1.4.1
1.4.1.post0
1.4.1.post1
1.5.0
1.5.0.post0
1.6.0
1.7.0
1.7.1
1.7.2
1.7.3
1.8.0
1.8.1
1.8.2
1.8.2.post0
1.8.2.post1
1.9.0
1.9.1
1.9.1.post0
1.9.2
1.9.2.post0
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-25297
PYSEC-2026-1503
GHSA-m238-fmcw-wh58
Jul 07, 2026
Label Studio allows Server-Side Request Forgery in the S3 Storage Endpoint
8.6
/ 10
High
Network
Low
None
None
Changed
High
None
None
DescriptionLabel Studio's S3 storage integration feature contains a Server-Side Request Forgery (SSRF) vulnerability in its endpoint configuration. When creating an S3 storage connection, the application allows users to specify a custom S3 endpoint URL via the s3_endpoint parameter. This endpoint URL is passed directly to the boto3 AWS SDK without proper validation or restrictions on the protocol or destination. The vulnerability allows an attacker to make the application send HTTP requests to arbitrary internal services by specifying them as the S3 endpoint. When the storage sync operation is triggered, the application attempts to make S3 API calls to the specified endpoint, effectively making HTTP requests to the target service and returning the response in error messages. This SSRF vulnerability enables attackers to bypass network segmentation and access internal services that should not be accessible from the external network. The vulnerability is particularly severe because error messages from failed requests contain the full response body, allowing data exfiltration from internal services. Steps to reproduce
The application will attempt to connect to the specified endpoint URL as if it were an S3 service. When the request fails due to invalid S3 API responses, the error message will contain the raw response from the internal service, allowing access to internal resources. Mitigations
ImpactThis vulnerability has high severity as it allows authenticated users to make requests to arbitrary internal services from the application server, potentially exposing sensitive internal resources and bypassing network segmentation. The inclusion of response data in error messages makes this particularly effective for data exfiltration. Affected versions
0.4.1
0.4.2
0.4.3
0.4.4
0.4.4.post1
0.4.4.post2
0.4.5
0.4.6
0.4.6.post1
0.4.6.post2
0.4.7
0.4.8
+ 76 more Show less
0.5.0
0.5.1
0.6.0
0.6.1
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.4.post0
0.7.4.post1
0.7.5.post1
0.7.5.post2
0.8.0
0.8.0.post0
0.8.1
0.8.1.post0
0.8.2
0.8.2.post0
0.9.0
0.9.0.post2
0.9.0.post3
0.9.0.post4
0.9.0.post5
0.9.1
0.9.1.post0
0.9.1.post1
0.9.1.post2
1.0.0
1.0.0.post0
1.0.0.post1
1.0.0.post2
1.0.0.post3
1.0.1
1.0.2
1.0.2.post0
1.1.0
1.1.0rc0
1.1.1
1.10.0
1.10.0.post0
1.10.1
1.11.0
1.12.0
1.12.0.post0
1.12.1
1.13.0
1.13.1
1.14.0
1.14.0.post0
1.15.0
1.2
1.3
1.3.post0
1.3.post1
1.4
1.4.1
1.4.1.post0
1.4.1.post1
1.5.0
1.5.0.post0
1.6.0
1.7.0
1.7.1
1.7.2
1.7.3
1.8.0
1.8.1
1.8.2
1.8.2.post0
1.8.2.post1
1.9.0
1.9.1
1.9.1.post0
1.9.2
1.9.2.post0
Fixed in
1.16.0
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-25296
PYSEC-2026-1504
GHSA-wpq5-3366-mqw4
Jul 07, 2026
Label Studio allows Cross-Site Scripting (XSS) via GET request to `/projects/upload-example` endpoint
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
DescriptionLabel Studio's The vulnerability exists because the upload-example endpoint renders user-provided HTML content without proper sanitization on a GET request. This allows attackers to inject and execute arbitrary JavaScript in victims' browsers by getting them to visit a maliciously crafted URL. This is considered vulnerable because it enables attackers to execute JavaScript in victims' contexts, potentially allowing theft of sensitive data, session hijacking, or other malicious actions. Steps to reproduce
When executed, the payload causes the application to render an HTML page containing an img tag that fails to load, triggering the onerror event handler which executes base64-decoded JavaScript, demonstrating successful XSS execution in the victim's browser. Mitigations
ImpactThe vulnerability requires no special privileges and can be exploited by getting a victim to visit a crafted URL. The impact is high as it allows arbitrary JavaScript execution in victims' browsers, potentially exposing sensitive data or enabling account takeover through session theft. Affected versions
0.4.1
0.4.2
0.4.3
0.4.4
0.4.4.post1
0.4.4.post2
0.4.5
0.4.6
0.4.6.post1
0.4.6.post2
0.4.7
0.4.8
+ 76 more Show less
0.5.0
0.5.1
0.6.0
0.6.1
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.4.post0
0.7.4.post1
0.7.5.post1
0.7.5.post2
0.8.0
0.8.0.post0
0.8.1
0.8.1.post0
0.8.2
0.8.2.post0
0.9.0
0.9.0.post2
0.9.0.post3
0.9.0.post4
0.9.0.post5
0.9.1
0.9.1.post0
0.9.1.post1
0.9.1.post2
1.0.0
1.0.0.post0
1.0.0.post1
1.0.0.post2
1.0.0.post3
1.0.1
1.0.2
1.0.2.post0
1.1.0
1.1.0rc0
1.1.1
1.10.0
1.10.0.post0
1.10.1
1.11.0
1.12.0
1.12.0.post0
1.12.1
1.13.0
1.13.1
1.14.0
1.14.0.post0
1.15.0
1.2
1.3
1.3.post0
1.3.post1
1.4
1.4.1
1.4.1.post0
1.4.1.post1
1.5.0
1.5.0.post0
1.6.0
1.7.0
1.7.1
1.7.2
1.7.3
1.8.0
1.8.1
1.8.2
1.8.2.post0
1.8.2.post1
1.9.0
1.9.1
1.9.1.post0
1.9.2
1.9.2.post0
Fixed in
1.16.0
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-47783
GHSA-8jhr-wpcm-hh4h
PYSEC-2025-124
May 15, 2025
label-studio vulnerable to Cross-Site Scripting (Reflected) via the label_config parameter.
High
Network
Low
None
SummaryThe vulnerability allows an attacker to inject a malicious script into the context of a web page, which can lead to data theft, unauthorized actions on behalf of the user, and other attacks. DetailsThe vulnerability is reproducible when sending a properly formatted request to the
The vulnerability is specifically located in line 57, where HttpResponse is used.
PoCSend the following request after changing the
Or you can create a vulnerable HTML page by changing
Impact
Affected versions
0.4.1
0.4.2
0.4.3
0.4.4
0.4.4.post1
0.4.4.post2
0.4.5
0.4.6
0.4.6.post1
0.4.6.post2
0.4.7
0.4.8
+ 78 more Show less
0.5.0
0.5.1
0.6.0
0.6.1
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.4.post0
0.7.4.post1
0.7.5.post1
0.7.5.post2
0.8.0
0.8.0.post0
0.8.1
0.8.1.post0
0.8.2
0.8.2.post0
0.9.0
0.9.0.post2
0.9.0.post3
0.9.0.post4
0.9.0.post5
0.9.1
0.9.1.post0
0.9.1.post1
0.9.1.post2
1.0.0
1.0.0.post0
1.0.0.post1
1.0.0.post2
1.0.0.post3
1.0.1
1.0.2
1.0.2.post0
1.1.0
1.1.0rc0
1.1.1
1.10.0
1.10.0.post0
1.10.1
1.11.0
1.12.0
1.12.0.post0
1.12.1
1.13.0
1.13.1
1.14.0
1.14.0.post0
1.15.0
1.16.0
1.17.0
1.2
1.3
1.3.post0
1.3.post1
1.4
1.4.1
1.4.1.post0
1.4.1.post1
1.5.0
1.5.0.post0
1.6.0
1.7.0
1.7.1
1.7.2
1.7.3
1.8.0
1.8.1
1.8.2
1.8.2.post0
1.8.2.post1
1.9.0
1.9.1
1.9.1.post0
1.9.2
1.9.2.post0
Fixed in
1.18.0
References
Updated Jun 06, 2026 · Source: OSV.dev
CVE-2024-26152
PYSEC-2024-249
GHSA-6xv9-957j-qfhg
Feb 22, 2024
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
SummaryOn all Label Studio versions prior to 1.11.0, data imported via file upload feature is not properly sanitized prior to being rendered within a DetailsNeed permission to use the "data import" function. This was reproduced on Label Studio 1.10.1. PoC
The following are the contents of the files used in the PoC
ImpactMalicious scripts can be injected into the code, and when linked with vulnerabilities such as CSRF, it can cause even greater damage. In particular, It can become a source of further attacks, especially when linked to social engineering. Affected versions
0.4.1
0.4.2
0.4.3
0.4.4
0.4.4.post1
0.4.4.post2
0.4.5
0.4.6
0.4.6.post1
0.4.6.post2
0.4.7
0.4.8
+ 113 more Show less
0.5.0
0.5.1
0.6.0
0.6.1
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.4.post0
0.7.4.post1
0.7.5.post1
0.7.5.post2
0.8.0
0.8.0.post0
0.8.1
0.8.1.post0
0.8.2
0.8.2.post0
0.9.0
0.9.0.post2
0.9.0.post3
0.9.0.post4
0.9.0.post5
0.9.1
0.9.1.post0
0.9.1.post1
0.9.1.post2
1.0.0
1.0.0.post0
1.0.0.post1
1.0.0.post2
1.0.0.post3
1.0.1
1.0.2
1.0.2.post0
1.1.0
1.1.0rc0
1.1.1
1.10.0
1.10.0.post0
1.10.1
1.2
1.3
1.3.post0
1.3.post1
1.4
1.4.1
1.4.1.post0
1.4.1.post1
1.5.0
1.5.0.post0
1.6.0
1.7.0
1.7.1
1.7.2
1.7.3
1.8.0
1.8.1
1.8.2
1.8.2.post0
1.8.2.post1
1.9.0
1.9.1
1.9.1.post0
1.9.2
1.9.2.post0
v1.4.1
v1.4.0
v1.3.0
v1.2.0
v1.1.1
v1.1.0
v1.0.2
v1.0.1
v1.0.0
v0.9.1.post1
v0.9.1.post0
v0.9.0.post5
v0.9.0.post4
v0.9.0.post3
v0.9.0
v0.8.2
v0.8.1
v0.8.0
v0.7.5.post0
v0.7.3
v0.7.2
v0.7.1
v0.7.0
v0.6.1
v0.6.0
v0.5.1
v0.4.8
v0.4.7
v0.4.6
v0.4.5
v0.4.4
v0.4.0
v0.3.0
v0.2.2
v.0.2.1-8
v.0.2.1-5
v.0.2.1-4
v.0.2.1-3
v.0.2.1-2
v.0.2.0
v.0.1.6
v.0.1.5
v.0.1.4
v.0.1.2
v.0.1.1
v.0.1.0
Fixed in
1.11.0
References
Updated Jun 10, 2026 · Source: OSV.dev
CVE-2023-47116
GHSA-p59w-9gqw-wj8r
PYSEC-2024-127
Jan 31, 2024
Label Studio SSRF on Import Bypassing `SSRF_PROTECTION_ENABLED` Protections
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
IntroductionThis write-up describes a vulnerability found in Label Studio, a popular open source data labeling tool. The vulnerability affects all versions of Label Studio prior to OverviewLabel Studio's SSRF protections that can be enabled by setting the DescriptionThe following
The
The issue here is the SSRF validation is only performed before the request is sent, and does not validate the destination IP address. Therefore, an attacker can either redirect the request or perform a DNS rebinding attack to bypass this protection. Proof of ConceptBoth the HTTP redirection and DNS rebinding methods for bypassing Label Studio's SSRF protections are explained below. HTTP RedirectionThe python
DNS Rebinding AttackDNS rebinding can bypass SSRF protections by resolving to an external IP address for the first resolution, but when the request is sent resolves to an internal IP address that is blocked. For an example, the domain ImpactSSRF vulnerabilities pose a significant risk on cloud environments, since instance credentials are managed by internal web APIs. An attacker can bypass Label Studio's SSRF protections to access internal web servers and partially compromise the confidentiality of those internal servers. Remediation Advice
Discovered
Affected versions
0.4.1
0.4.2
0.4.3
0.4.4
0.4.4.post1
0.4.4.post2
0.4.5
0.4.6
0.4.6.post1
0.4.6.post2
0.4.7
0.4.8
+ 67 more Show less
0.5.0
0.5.1
0.6.0
0.6.1
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.4.post0
0.7.4.post1
0.7.5.post1
0.7.5.post2
0.8.0
0.8.0.post0
0.8.1
0.8.1.post0
0.8.2
0.8.2.post0
0.9.0
0.9.0.post2
0.9.0.post3
0.9.0.post4
0.9.0.post5
0.9.1
0.9.1.post0
0.9.1.post1
0.9.1.post2
1.0.0
1.0.0.post0
1.0.0.post1
1.0.0.post2
1.0.0.post3
1.0.1
1.0.2
1.0.2.post0
1.1.0
1.1.0rc0
1.1.1
1.10.0
1.10.0.post0
1.10.1
1.2
1.3
1.3.post0
1.3.post1
1.4
1.4.1
1.4.1.post0
1.4.1.post1
1.5.0
1.5.0.post0
1.6.0
1.7.0
1.7.1
1.7.2
1.7.3
1.8.0
1.8.1
1.8.2
1.8.2.post0
1.8.2.post1
1.9.0
1.9.1
1.9.1.post0
1.9.2
1.9.2.post0
Fixed in
1.11.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-23633
GHSA-fq23-g58m-799r
PYSEC-2024-128
Jan 24, 2024
Cross-site Scripting Vulnerability on Data Import
4.7
/ 10
Medium
Network
Low
None
Required
Changed
Low
None
None
IntroductionThis write-up describes a vulnerability found in Label Studio, a popular open source data labeling tool. The vulnerability affects all versions of Label Studio prior to OverviewLabel Studio had a remote import feature allowed users to import data from a remote web source, that was downloaded and could be viewed on the website. This feature could had been abused to download a HTML file that executed malicious JavaScript code in the context of the Label Studio website. DescriptionThe following code snippet in Label Studio showed that is a URL passed the SSRF verification checks, the contents of the file would be downloaded using the filename in the URL.
The downloaded file path could then be retrieved by sending a request to
Since the Proof of ConceptBelow were the steps to recreate this issue:
ImpactExecuting arbitrary JavaScript could result in an attacker performing malicious actions on Label Studio users if they visit the crafted avatar image. For an example, an attacker can craft a JavaScript payload that adds a new Django Super Administrator user if a Django administrator visits the image. Remediation Advice
Discovered
Affected versions
0.4.1
0.4.2
0.4.3
0.4.4
0.4.4.post1
0.4.4.post2
0.4.5
0.4.6
0.4.6.post1
0.4.6.post2
0.4.7
0.4.8
+ 66 more Show less
0.5.0
0.5.1
0.6.0
0.6.1
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.4.post0
0.7.4.post1
0.7.5.post1
0.7.5.post2
0.8.0
0.8.0.post0
0.8.1
0.8.1.post0
0.8.2
0.8.2.post0
0.9.0
0.9.0.post2
0.9.0.post3
0.9.0.post4
0.9.0.post5
0.9.1
0.9.1.post0
0.9.1.post1
0.9.1.post2
1.0.0
1.0.0.post0
1.0.0.post1
1.0.0.post2
1.0.0.post3
1.0.1
1.0.2
1.0.2.post0
1.1.0
1.1.0rc0
1.1.1
1.10.0
1.10.0.post0
1.2
1.3
1.3.post0
1.3.post1
1.4
1.4.1
1.4.1.post0
1.4.1.post1
1.5.0
1.5.0.post0
1.6.0
1.7.0
1.7.1
1.7.2
1.7.3
1.8.0
1.8.1
1.8.2
1.8.2.post0
1.8.2.post1
1.9.0
1.9.1
1.9.1.post0
1.9.2
1.9.2.post0
Fixed in
1.10.1
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2023-47115
GHSA-q68h-xwq5-mm7x
PYSEC-2024-126
Jan 24, 2024
Cross-site Scripting Vulnerability on Avatar Upload
7.1
/ 10
High
Network
Low
None
Required
Changed
Low
Low
Low
IntroductionThis write-up describes a vulnerability found in Label Studio, a popular open source data labeling tool. The vulnerability affects all versions of Label Studio prior to OverviewLabel Studio has a cross-site scripting (XSS) vulnerability that could be exploited when an authenticated user uploads a crafted image file for their avatar that gets rendered as a HTML file on the website. DescriptionThe following code snippet in Label Studio shows that the only verification check is that the file is an image by extracting the dimensions from the file.
Label Studio serves avatar images using Django's built-in
The issue with the Django Proof of ConceptBelow are the steps to reproduce this issue and execute JavaScript code in the context of the Label Studio website.
ImpactExecuting arbitrary JavaScript could result in an attacker performing malicious actions on Label Studio users if they visit the crafted avatar image. For an example, an attacker can craft a JavaScript payload that adds a new Django Super Administrator user if a Django administrator visits the image. Remediation Advice
Discovered
Affected versions
0.4.1
0.4.2
0.4.3
0.4.4
0.4.4.post1
0.4.4.post2
0.4.5
0.4.6
0.4.6.post1
0.4.6.post2
0.4.7
0.4.8
+ 62 more Show less
0.5.0
0.5.1
0.6.0
0.6.1
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.4.post0
0.7.4.post1
0.7.5.post1
0.7.5.post2
0.8.0
0.8.0.post0
0.8.1
0.8.1.post0
0.8.2
0.8.2.post0
0.9.0
0.9.0.post2
0.9.0.post3
0.9.0.post4
0.9.0.post5
0.9.1
0.9.1.post0
0.9.1.post1
0.9.1.post2
1.0.0
1.0.0.post0
1.0.0.post1
1.0.0.post2
1.0.0.post3
1.0.1
1.0.2
1.0.2.post0
1.1.0
1.1.0rc0
1.1.1
1.2
1.3
1.3.post0
1.3.post1
1.4
1.4.1
1.4.1.post0
1.4.1.post1
1.5.0
1.5.0.post0
1.6.0
1.7.0
1.7.1
1.7.2
1.7.3
1.8.0
1.8.1
1.8.2
1.8.2.post0
1.8.2.post1
1.9.0
1.9.1
1.9.1.post0
Fixed in
1.9.2
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2023-47117
GHSA-6hjj-gq77-j4qw
PYSEC-2023-275
Nov 14, 2023
Label Studio Object Relational Mapper Leak Vulnerability in Filtering Task
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
IntroductionThis write-up describes a vulnerability found in Label Studio, a popular open source data labeling tool. The vulnerability affects all versions of Label Studio prior to OverviewIn all current versions of Label Studio, the application allows users to insecurely set filters for filtering tasks. An attacker can construct a filter chain to filter tasks based on sensitive fields for all user accounts on the platform by exploiting Django's Object Relational Mapper (ORM). Since the results of query can be manipulated by the ORM filter, an attacker can leak these sensitive fields character by character. For an example, the following filter chain will task results by the password hash of an account on Label Studio.
For consistency, this type of vulnerability will be termed as ORM Leak in the rest of this disclosure. In addition, Label Studio had a hard coded secret key that an attacker can use to forge a session token of any user by exploiting this ORM Leak vulnerability to leak account password hashes. DescriptionThe following code snippet from the
These
The
The following code snippet of the
Finally, the
Proof of ConceptBelow are the steps to exploit about how to exploit this vulnerability to leak the password hash of an account on Label Studio.
The following example GIF demonstrates exploiting this ORM Leak vulnerability to retrieve the password hash
ImpactThis vulnerability can be exploited to completely compromise the confidentiality of highly sensitive account information, such as account password hashes. For all versions Remediation Advice
Discovered
| ||
1.4.1.post0
pre
12 CVEs
CVE-2026-22033
PYSEC-2026-1502
GHSA-2mq9-hm29-8qch
Jul 07, 2026
Label Studio is vulnerable to full account takeover by chaining Stored XSS + IDOR in User Profile via custom_hotkeys field
Critical
Network
Low
Low
None
PrologueThese vulnerabilities have been found and chained by DCODX-AI. Validation of the exploit chain has been confirmed manually. SummaryA persistent stored cross-site scripting (XSS) vulnerability exists in the custom_hotkeys functionality of the application. An authenticated attacker (or one who can trick a user/administrator into updating their custom_hotkeys) can inject JavaScript code that executes in other users’ browsers when those users load any page using the DetailsWithin
Here, user.custom_hotkeys is run through json_dumps_ensure_ascii (in In
The serializer allows
When another user loads a page using templates/base.html (for example PoC
Example request
Example response
ImpactExploitation impact:
Who is impacted:
Affected versions
0.4.1
0.4.2
0.4.3
0.4.4
0.4.4.post1
0.4.4.post2
0.4.5
0.4.6
0.4.6.post1
0.4.6.post2
0.4.7
0.4.8
+ 83 more Show less
0.5.0
0.5.1
0.6.0
0.6.1
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.4.post0
0.7.4.post1
0.7.5.post1
0.7.5.post2
0.8.0
0.8.0.post0
0.8.1
0.8.1.post0
0.8.2
0.8.2.post0
0.9.0
0.9.0.post2
0.9.0.post3
0.9.0.post4
0.9.0.post5
0.9.1
0.9.1.post0
0.9.1.post1
0.9.1.post2
1.0.0
1.0.0.post0
1.0.0.post1
1.0.0.post2
1.0.0.post3
1.0.1
1.0.2
1.0.2.post0
1.1.0
1.1.0rc0
1.1.1
1.10.0
1.10.0.post0
1.10.1
1.11.0
1.12.0
1.12.0.post0
1.12.1
1.13.0
1.13.1
1.14.0
1.14.0.post0
1.15.0
1.16.0
1.17.0
1.18.0
1.19.0
1.2
1.20.0
1.21.0
1.22.0
1.3
1.3.post0
1.3.post1
1.4
1.4.1
1.4.1.post0
1.4.1.post1
1.5.0
1.5.0.post0
1.6.0
1.7.0
1.7.1
1.7.2
1.7.3
1.8.0
1.8.1
1.8.2
1.8.2.post0
1.8.2.post1
1.9.0
1.9.1
1.9.1.post0
1.9.2
1.9.2.post0
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-25297
PYSEC-2026-1503
GHSA-m238-fmcw-wh58
Jul 07, 2026
Label Studio allows Server-Side Request Forgery in the S3 Storage Endpoint
8.6
/ 10
High
Network
Low
None
None
Changed
High
None
None
DescriptionLabel Studio's S3 storage integration feature contains a Server-Side Request Forgery (SSRF) vulnerability in its endpoint configuration. When creating an S3 storage connection, the application allows users to specify a custom S3 endpoint URL via the s3_endpoint parameter. This endpoint URL is passed directly to the boto3 AWS SDK without proper validation or restrictions on the protocol or destination. The vulnerability allows an attacker to make the application send HTTP requests to arbitrary internal services by specifying them as the S3 endpoint. When the storage sync operation is triggered, the application attempts to make S3 API calls to the specified endpoint, effectively making HTTP requests to the target service and returning the response in error messages. This SSRF vulnerability enables attackers to bypass network segmentation and access internal services that should not be accessible from the external network. The vulnerability is particularly severe because error messages from failed requests contain the full response body, allowing data exfiltration from internal services. Steps to reproduce
The application will attempt to connect to the specified endpoint URL as if it were an S3 service. When the request fails due to invalid S3 API responses, the error message will contain the raw response from the internal service, allowing access to internal resources. Mitigations
ImpactThis vulnerability has high severity as it allows authenticated users to make requests to arbitrary internal services from the application server, potentially exposing sensitive internal resources and bypassing network segmentation. The inclusion of response data in error messages makes this particularly effective for data exfiltration. Affected versions
0.4.1
0.4.2
0.4.3
0.4.4
0.4.4.post1
0.4.4.post2
0.4.5
0.4.6
0.4.6.post1
0.4.6.post2
0.4.7
0.4.8
+ 76 more Show less
0.5.0
0.5.1
0.6.0
0.6.1
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.4.post0
0.7.4.post1
0.7.5.post1
0.7.5.post2
0.8.0
0.8.0.post0
0.8.1
0.8.1.post0
0.8.2
0.8.2.post0
0.9.0
0.9.0.post2
0.9.0.post3
0.9.0.post4
0.9.0.post5
0.9.1
0.9.1.post0
0.9.1.post1
0.9.1.post2
1.0.0
1.0.0.post0
1.0.0.post1
1.0.0.post2
1.0.0.post3
1.0.1
1.0.2
1.0.2.post0
1.1.0
1.1.0rc0
1.1.1
1.10.0
1.10.0.post0
1.10.1
1.11.0
1.12.0
1.12.0.post0
1.12.1
1.13.0
1.13.1
1.14.0
1.14.0.post0
1.15.0
1.2
1.3
1.3.post0
1.3.post1
1.4
1.4.1
1.4.1.post0
1.4.1.post1
1.5.0
1.5.0.post0
1.6.0
1.7.0
1.7.1
1.7.2
1.7.3
1.8.0
1.8.1
1.8.2
1.8.2.post0
1.8.2.post1
1.9.0
1.9.1
1.9.1.post0
1.9.2
1.9.2.post0
Fixed in
1.16.0
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-25296
PYSEC-2026-1504
GHSA-wpq5-3366-mqw4
Jul 07, 2026
Label Studio allows Cross-Site Scripting (XSS) via GET request to `/projects/upload-example` endpoint
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
DescriptionLabel Studio's The vulnerability exists because the upload-example endpoint renders user-provided HTML content without proper sanitization on a GET request. This allows attackers to inject and execute arbitrary JavaScript in victims' browsers by getting them to visit a maliciously crafted URL. This is considered vulnerable because it enables attackers to execute JavaScript in victims' contexts, potentially allowing theft of sensitive data, session hijacking, or other malicious actions. Steps to reproduce
When executed, the payload causes the application to render an HTML page containing an img tag that fails to load, triggering the onerror event handler which executes base64-decoded JavaScript, demonstrating successful XSS execution in the victim's browser. Mitigations
ImpactThe vulnerability requires no special privileges and can be exploited by getting a victim to visit a crafted URL. The impact is high as it allows arbitrary JavaScript execution in victims' browsers, potentially exposing sensitive data or enabling account takeover through session theft. Affected versions
0.4.1
0.4.2
0.4.3
0.4.4
0.4.4.post1
0.4.4.post2
0.4.5
0.4.6
0.4.6.post1
0.4.6.post2
0.4.7
0.4.8
+ 76 more Show less
0.5.0
0.5.1
0.6.0
0.6.1
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.4.post0
0.7.4.post1
0.7.5.post1
0.7.5.post2
0.8.0
0.8.0.post0
0.8.1
0.8.1.post0
0.8.2
0.8.2.post0
0.9.0
0.9.0.post2
0.9.0.post3
0.9.0.post4
0.9.0.post5
0.9.1
0.9.1.post0
0.9.1.post1
0.9.1.post2
1.0.0
1.0.0.post0
1.0.0.post1
1.0.0.post2
1.0.0.post3
1.0.1
1.0.2
1.0.2.post0
1.1.0
1.1.0rc0
1.1.1
1.10.0
1.10.0.post0
1.10.1
1.11.0
1.12.0
1.12.0.post0
1.12.1
1.13.0
1.13.1
1.14.0
1.14.0.post0
1.15.0
1.2
1.3
1.3.post0
1.3.post1
1.4
1.4.1
1.4.1.post0
1.4.1.post1
1.5.0
1.5.0.post0
1.6.0
1.7.0
1.7.1
1.7.2
1.7.3
1.8.0
1.8.1
1.8.2
1.8.2.post0
1.8.2.post1
1.9.0
1.9.1
1.9.1.post0
1.9.2
1.9.2.post0
Fixed in
1.16.0
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-47783
GHSA-8jhr-wpcm-hh4h
PYSEC-2025-124
May 15, 2025
label-studio vulnerable to Cross-Site Scripting (Reflected) via the label_config parameter.
High
Network
Low
None
SummaryThe vulnerability allows an attacker to inject a malicious script into the context of a web page, which can lead to data theft, unauthorized actions on behalf of the user, and other attacks. DetailsThe vulnerability is reproducible when sending a properly formatted request to the
The vulnerability is specifically located in line 57, where HttpResponse is used.
PoCSend the following request after changing the
Or you can create a vulnerable HTML page by changing
Impact
Affected versions
0.4.1
0.4.2
0.4.3
0.4.4
0.4.4.post1
0.4.4.post2
0.4.5
0.4.6
0.4.6.post1
0.4.6.post2
0.4.7
0.4.8
+ 78 more Show less
0.5.0
0.5.1
0.6.0
0.6.1
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.4.post0
0.7.4.post1
0.7.5.post1
0.7.5.post2
0.8.0
0.8.0.post0
0.8.1
0.8.1.post0
0.8.2
0.8.2.post0
0.9.0
0.9.0.post2
0.9.0.post3
0.9.0.post4
0.9.0.post5
0.9.1
0.9.1.post0
0.9.1.post1
0.9.1.post2
1.0.0
1.0.0.post0
1.0.0.post1
1.0.0.post2
1.0.0.post3
1.0.1
1.0.2
1.0.2.post0
1.1.0
1.1.0rc0
1.1.1
1.10.0
1.10.0.post0
1.10.1
1.11.0
1.12.0
1.12.0.post0
1.12.1
1.13.0
1.13.1
1.14.0
1.14.0.post0
1.15.0
1.16.0
1.17.0
1.2
1.3
1.3.post0
1.3.post1
1.4
1.4.1
1.4.1.post0
1.4.1.post1
1.5.0
1.5.0.post0
1.6.0
1.7.0
1.7.1
1.7.2
1.7.3
1.8.0
1.8.1
1.8.2
1.8.2.post0
1.8.2.post1
1.9.0
1.9.1
1.9.1.post0
1.9.2
1.9.2.post0
Fixed in
1.18.0
References
Updated Jun 06, 2026 · Source: OSV.dev
CVE-2024-26152
PYSEC-2024-249
GHSA-6xv9-957j-qfhg
Feb 22, 2024
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
SummaryOn all Label Studio versions prior to 1.11.0, data imported via file upload feature is not properly sanitized prior to being rendered within a DetailsNeed permission to use the "data import" function. This was reproduced on Label Studio 1.10.1. PoC
The following are the contents of the files used in the PoC
ImpactMalicious scripts can be injected into the code, and when linked with vulnerabilities such as CSRF, it can cause even greater damage. In particular, It can become a source of further attacks, especially when linked to social engineering. Affected versions
0.4.1
0.4.2
0.4.3
0.4.4
0.4.4.post1
0.4.4.post2
0.4.5
0.4.6
0.4.6.post1
0.4.6.post2
0.4.7
0.4.8
+ 113 more Show less
0.5.0
0.5.1
0.6.0
0.6.1
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.4.post0
0.7.4.post1
0.7.5.post1
0.7.5.post2
0.8.0
0.8.0.post0
0.8.1
0.8.1.post0
0.8.2
0.8.2.post0
0.9.0
0.9.0.post2
0.9.0.post3
0.9.0.post4
0.9.0.post5
0.9.1
0.9.1.post0
0.9.1.post1
0.9.1.post2
1.0.0
1.0.0.post0
1.0.0.post1
1.0.0.post2
1.0.0.post3
1.0.1
1.0.2
1.0.2.post0
1.1.0
1.1.0rc0
1.1.1
1.10.0
1.10.0.post0
1.10.1
1.2
1.3
1.3.post0
1.3.post1
1.4
1.4.1
1.4.1.post0
1.4.1.post1
1.5.0
1.5.0.post0
1.6.0
1.7.0
1.7.1
1.7.2
1.7.3
1.8.0
1.8.1
1.8.2
1.8.2.post0
1.8.2.post1
1.9.0
1.9.1
1.9.1.post0
1.9.2
1.9.2.post0
v1.4.1
v1.4.0
v1.3.0
v1.2.0
v1.1.1
v1.1.0
v1.0.2
v1.0.1
v1.0.0
v0.9.1.post1
v0.9.1.post0
v0.9.0.post5
v0.9.0.post4
v0.9.0.post3
v0.9.0
v0.8.2
v0.8.1
v0.8.0
v0.7.5.post0
v0.7.3
v0.7.2
v0.7.1
v0.7.0
v0.6.1
v0.6.0
v0.5.1
v0.4.8
v0.4.7
v0.4.6
v0.4.5
v0.4.4
v0.4.0
v0.3.0
v0.2.2
v.0.2.1-8
v.0.2.1-5
v.0.2.1-4
v.0.2.1-3
v.0.2.1-2
v.0.2.0
v.0.1.6
v.0.1.5
v.0.1.4
v.0.1.2
v.0.1.1
v.0.1.0
Fixed in
1.11.0
References
Updated Jun 10, 2026 · Source: OSV.dev
CVE-2023-47116
GHSA-p59w-9gqw-wj8r
PYSEC-2024-127
Jan 31, 2024
Label Studio SSRF on Import Bypassing `SSRF_PROTECTION_ENABLED` Protections
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
IntroductionThis write-up describes a vulnerability found in Label Studio, a popular open source data labeling tool. The vulnerability affects all versions of Label Studio prior to OverviewLabel Studio's SSRF protections that can be enabled by setting the DescriptionThe following
The
The issue here is the SSRF validation is only performed before the request is sent, and does not validate the destination IP address. Therefore, an attacker can either redirect the request or perform a DNS rebinding attack to bypass this protection. Proof of ConceptBoth the HTTP redirection and DNS rebinding methods for bypassing Label Studio's SSRF protections are explained below. HTTP RedirectionThe python
DNS Rebinding AttackDNS rebinding can bypass SSRF protections by resolving to an external IP address for the first resolution, but when the request is sent resolves to an internal IP address that is blocked. For an example, the domain ImpactSSRF vulnerabilities pose a significant risk on cloud environments, since instance credentials are managed by internal web APIs. An attacker can bypass Label Studio's SSRF protections to access internal web servers and partially compromise the confidentiality of those internal servers. Remediation Advice
Discovered
Affected versions
0.4.1
0.4.2
0.4.3
0.4.4
0.4.4.post1
0.4.4.post2
0.4.5
0.4.6
0.4.6.post1
0.4.6.post2
0.4.7
0.4.8
+ 67 more Show less
0.5.0
0.5.1
0.6.0
0.6.1
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.4.post0
0.7.4.post1
0.7.5.post1
0.7.5.post2
0.8.0
0.8.0.post0
0.8.1
0.8.1.post0
0.8.2
0.8.2.post0
0.9.0
0.9.0.post2
0.9.0.post3
0.9.0.post4
0.9.0.post5
0.9.1
0.9.1.post0
0.9.1.post1
0.9.1.post2
1.0.0
1.0.0.post0
1.0.0.post1
1.0.0.post2
1.0.0.post3
1.0.1
1.0.2
1.0.2.post0
1.1.0
1.1.0rc0
1.1.1
1.10.0
1.10.0.post0
1.10.1
1.2
1.3
1.3.post0
1.3.post1
1.4
1.4.1
1.4.1.post0
1.4.1.post1
1.5.0
1.5.0.post0
1.6.0
1.7.0
1.7.1
1.7.2
1.7.3
1.8.0
1.8.1
1.8.2
1.8.2.post0
1.8.2.post1
1.9.0
1.9.1
1.9.1.post0
1.9.2
1.9.2.post0
Fixed in
1.11.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-23633
GHSA-fq23-g58m-799r
PYSEC-2024-128
Jan 24, 2024
Cross-site Scripting Vulnerability on Data Import
4.7
/ 10
Medium
Network
Low
None
Required
Changed
Low
None
None
IntroductionThis write-up describes a vulnerability found in Label Studio, a popular open source data labeling tool. The vulnerability affects all versions of Label Studio prior to OverviewLabel Studio had a remote import feature allowed users to import data from a remote web source, that was downloaded and could be viewed on the website. This feature could had been abused to download a HTML file that executed malicious JavaScript code in the context of the Label Studio website. DescriptionThe following code snippet in Label Studio showed that is a URL passed the SSRF verification checks, the contents of the file would be downloaded using the filename in the URL.
The downloaded file path could then be retrieved by sending a request to
Since the Proof of ConceptBelow were the steps to recreate this issue:
ImpactExecuting arbitrary JavaScript could result in an attacker performing malicious actions on Label Studio users if they visit the crafted avatar image. For an example, an attacker can craft a JavaScript payload that adds a new Django Super Administrator user if a Django administrator visits the image. Remediation Advice
Discovered
Affected versions
0.4.1
0.4.2
0.4.3
0.4.4
0.4.4.post1
0.4.4.post2
0.4.5
0.4.6
0.4.6.post1
0.4.6.post2
0.4.7
0.4.8
+ 66 more Show less
0.5.0
0.5.1
0.6.0
0.6.1
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.4.post0
0.7.4.post1
0.7.5.post1
0.7.5.post2
0.8.0
0.8.0.post0
0.8.1
0.8.1.post0
0.8.2
0.8.2.post0
0.9.0
0.9.0.post2
0.9.0.post3
0.9.0.post4
0.9.0.post5
0.9.1
0.9.1.post0
0.9.1.post1
0.9.1.post2
1.0.0
1.0.0.post0
1.0.0.post1
1.0.0.post2
1.0.0.post3
1.0.1
1.0.2
1.0.2.post0
1.1.0
1.1.0rc0
1.1.1
1.10.0
1.10.0.post0
1.2
1.3
1.3.post0
1.3.post1
1.4
1.4.1
1.4.1.post0
1.4.1.post1
1.5.0
1.5.0.post0
1.6.0
1.7.0
1.7.1
1.7.2
1.7.3
1.8.0
1.8.1
1.8.2
1.8.2.post0
1.8.2.post1
1.9.0
1.9.1
1.9.1.post0
1.9.2
1.9.2.post0
Fixed in
1.10.1
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2023-47115
GHSA-q68h-xwq5-mm7x
PYSEC-2024-126
Jan 24, 2024
Cross-site Scripting Vulnerability on Avatar Upload
7.1
/ 10
High
Network
Low
None
Required
Changed
Low
Low
Low
IntroductionThis write-up describes a vulnerability found in Label Studio, a popular open source data labeling tool. The vulnerability affects all versions of Label Studio prior to OverviewLabel Studio has a cross-site scripting (XSS) vulnerability that could be exploited when an authenticated user uploads a crafted image file for their avatar that gets rendered as a HTML file on the website. DescriptionThe following code snippet in Label Studio shows that the only verification check is that the file is an image by extracting the dimensions from the file.
Label Studio serves avatar images using Django's built-in
The issue with the Django Proof of ConceptBelow are the steps to reproduce this issue and execute JavaScript code in the context of the Label Studio website.
ImpactExecuting arbitrary JavaScript could result in an attacker performing malicious actions on Label Studio users if they visit the crafted avatar image. For an example, an attacker can craft a JavaScript payload that adds a new Django Super Administrator user if a Django administrator visits the image. Remediation Advice
Discovered
Affected versions
0.4.1
0.4.2
0.4.3
0.4.4
0.4.4.post1
0.4.4.post2
0.4.5
0.4.6
0.4.6.post1
0.4.6.post2
0.4.7
0.4.8
+ 62 more Show less
0.5.0
0.5.1
0.6.0
0.6.1
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.4.post0
0.7.4.post1
0.7.5.post1
0.7.5.post2
0.8.0
0.8.0.post0
0.8.1
0.8.1.post0
0.8.2
0.8.2.post0
0.9.0
0.9.0.post2
0.9.0.post3
0.9.0.post4
0.9.0.post5
0.9.1
0.9.1.post0
0.9.1.post1
0.9.1.post2
1.0.0
1.0.0.post0
1.0.0.post1
1.0.0.post2
1.0.0.post3
1.0.1
1.0.2
1.0.2.post0
1.1.0
1.1.0rc0
1.1.1
1.2
1.3
1.3.post0
1.3.post1
1.4
1.4.1
1.4.1.post0
1.4.1.post1
1.5.0
1.5.0.post0
1.6.0
1.7.0
1.7.1
1.7.2
1.7.3
1.8.0
1.8.1
1.8.2
1.8.2.post0
1.8.2.post1
1.9.0
1.9.1
1.9.1.post0
Fixed in
1.9.2
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2023-47117
GHSA-6hjj-gq77-j4qw
PYSEC-2023-275
Nov 14, 2023
Label Studio Object Relational Mapper Leak Vulnerability in Filtering Task
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
IntroductionThis write-up describes a vulnerability found in Label Studio, a popular open source data labeling tool. The vulnerability affects all versions of Label Studio prior to OverviewIn all current versions of Label Studio, the application allows users to insecurely set filters for filtering tasks. An attacker can construct a filter chain to filter tasks based on sensitive fields for all user accounts on the platform by exploiting Django's Object Relational Mapper (ORM). Since the results of query can be manipulated by the ORM filter, an attacker can leak these sensitive fields character by character. For an example, the following filter chain will task results by the password hash of an account on Label Studio.
For consistency, this type of vulnerability will be termed as ORM Leak in the rest of this disclosure. In addition, Label Studio had a hard coded secret key that an attacker can use to forge a session token of any user by exploiting this ORM Leak vulnerability to leak account password hashes. DescriptionThe following code snippet from the
These
The
The following code snippet of the
Finally, the
Proof of ConceptBelow are the steps to exploit about how to exploit this vulnerability to leak the password hash of an account on Label Studio.
The following example GIF demonstrates exploiting this ORM Leak vulnerability to retrieve the password hash
ImpactThis vulnerability can be exploited to completely compromise the confidentiality of highly sensitive account information, such as account password hashes. For all versions Remediation Advice
Discovered
| ||
1.4.1
patch
12 CVEs
CVE-2026-22033
PYSEC-2026-1502
GHSA-2mq9-hm29-8qch
Jul 07, 2026
Label Studio is vulnerable to full account takeover by chaining Stored XSS + IDOR in User Profile via custom_hotkeys field
Critical
Network
Low
Low
None
PrologueThese vulnerabilities have been found and chained by DCODX-AI. Validation of the exploit chain has been confirmed manually. SummaryA persistent stored cross-site scripting (XSS) vulnerability exists in the custom_hotkeys functionality of the application. An authenticated attacker (or one who can trick a user/administrator into updating their custom_hotkeys) can inject JavaScript code that executes in other users’ browsers when those users load any page using the DetailsWithin
Here, user.custom_hotkeys is run through json_dumps_ensure_ascii (in In
The serializer allows
When another user loads a page using templates/base.html (for example PoC
Example request
Example response
ImpactExploitation impact:
Who is impacted:
Affected versions
0.4.1
0.4.2
0.4.3
0.4.4
0.4.4.post1
0.4.4.post2
0.4.5
0.4.6
0.4.6.post1
0.4.6.post2
0.4.7
0.4.8
+ 83 more Show less
0.5.0
0.5.1
0.6.0
0.6.1
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.4.post0
0.7.4.post1
0.7.5.post1
0.7.5.post2
0.8.0
0.8.0.post0
0.8.1
0.8.1.post0
0.8.2
0.8.2.post0
0.9.0
0.9.0.post2
0.9.0.post3
0.9.0.post4
0.9.0.post5
0.9.1
0.9.1.post0
0.9.1.post1
0.9.1.post2
1.0.0
1.0.0.post0
1.0.0.post1
1.0.0.post2
1.0.0.post3
1.0.1
1.0.2
1.0.2.post0
1.1.0
1.1.0rc0
1.1.1
1.10.0
1.10.0.post0
1.10.1
1.11.0
1.12.0
1.12.0.post0
1.12.1
1.13.0
1.13.1
1.14.0
1.14.0.post0
1.15.0
1.16.0
1.17.0
1.18.0
1.19.0
1.2
1.20.0
1.21.0
1.22.0
1.3
1.3.post0
1.3.post1
1.4
1.4.1
1.4.1.post0
1.4.1.post1
1.5.0
1.5.0.post0
1.6.0
1.7.0
1.7.1
1.7.2
1.7.3
1.8.0
1.8.1
1.8.2
1.8.2.post0
1.8.2.post1
1.9.0
1.9.1
1.9.1.post0
1.9.2
1.9.2.post0
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-25297
PYSEC-2026-1503
GHSA-m238-fmcw-wh58
Jul 07, 2026
Label Studio allows Server-Side Request Forgery in the S3 Storage Endpoint
8.6
/ 10
High
Network
Low
None
None
Changed
High
None
None
DescriptionLabel Studio's S3 storage integration feature contains a Server-Side Request Forgery (SSRF) vulnerability in its endpoint configuration. When creating an S3 storage connection, the application allows users to specify a custom S3 endpoint URL via the s3_endpoint parameter. This endpoint URL is passed directly to the boto3 AWS SDK without proper validation or restrictions on the protocol or destination. The vulnerability allows an attacker to make the application send HTTP requests to arbitrary internal services by specifying them as the S3 endpoint. When the storage sync operation is triggered, the application attempts to make S3 API calls to the specified endpoint, effectively making HTTP requests to the target service and returning the response in error messages. This SSRF vulnerability enables attackers to bypass network segmentation and access internal services that should not be accessible from the external network. The vulnerability is particularly severe because error messages from failed requests contain the full response body, allowing data exfiltration from internal services. Steps to reproduce
The application will attempt to connect to the specified endpoint URL as if it were an S3 service. When the request fails due to invalid S3 API responses, the error message will contain the raw response from the internal service, allowing access to internal resources. Mitigations
ImpactThis vulnerability has high severity as it allows authenticated users to make requests to arbitrary internal services from the application server, potentially exposing sensitive internal resources and bypassing network segmentation. The inclusion of response data in error messages makes this particularly effective for data exfiltration. Affected versions
0.4.1
0.4.2
0.4.3
0.4.4
0.4.4.post1
0.4.4.post2
0.4.5
0.4.6
0.4.6.post1
0.4.6.post2
0.4.7
0.4.8
+ 76 more Show less
0.5.0
0.5.1
0.6.0
0.6.1
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.4.post0
0.7.4.post1
0.7.5.post1
0.7.5.post2
0.8.0
0.8.0.post0
0.8.1
0.8.1.post0
0.8.2
0.8.2.post0
0.9.0
0.9.0.post2
0.9.0.post3
0.9.0.post4
0.9.0.post5
0.9.1
0.9.1.post0
0.9.1.post1
0.9.1.post2
1.0.0
1.0.0.post0
1.0.0.post1
1.0.0.post2
1.0.0.post3
1.0.1
1.0.2
1.0.2.post0
1.1.0
1.1.0rc0
1.1.1
1.10.0
1.10.0.post0
1.10.1
1.11.0
1.12.0
1.12.0.post0
1.12.1
1.13.0
1.13.1
1.14.0
1.14.0.post0
1.15.0
1.2
1.3
1.3.post0
1.3.post1
1.4
1.4.1
1.4.1.post0
1.4.1.post1
1.5.0
1.5.0.post0
1.6.0
1.7.0
1.7.1
1.7.2
1.7.3
1.8.0
1.8.1
1.8.2
1.8.2.post0
1.8.2.post1
1.9.0
1.9.1
1.9.1.post0
1.9.2
1.9.2.post0
Fixed in
1.16.0
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-25296
PYSEC-2026-1504
GHSA-wpq5-3366-mqw4
Jul 07, 2026
Label Studio allows Cross-Site Scripting (XSS) via GET request to `/projects/upload-example` endpoint
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
DescriptionLabel Studio's The vulnerability exists because the upload-example endpoint renders user-provided HTML content without proper sanitization on a GET request. This allows attackers to inject and execute arbitrary JavaScript in victims' browsers by getting them to visit a maliciously crafted URL. This is considered vulnerable because it enables attackers to execute JavaScript in victims' contexts, potentially allowing theft of sensitive data, session hijacking, or other malicious actions. Steps to reproduce
When executed, the payload causes the application to render an HTML page containing an img tag that fails to load, triggering the onerror event handler which executes base64-decoded JavaScript, demonstrating successful XSS execution in the victim's browser. Mitigations
ImpactThe vulnerability requires no special privileges and can be exploited by getting a victim to visit a crafted URL. The impact is high as it allows arbitrary JavaScript execution in victims' browsers, potentially exposing sensitive data or enabling account takeover through session theft. Affected versions
0.4.1
0.4.2
0.4.3
0.4.4
0.4.4.post1
0.4.4.post2
0.4.5
0.4.6
0.4.6.post1
0.4.6.post2
0.4.7
0.4.8
+ 76 more Show less
0.5.0
0.5.1
0.6.0
0.6.1
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.4.post0
0.7.4.post1
0.7.5.post1
0.7.5.post2
0.8.0
0.8.0.post0
0.8.1
0.8.1.post0
0.8.2
0.8.2.post0
0.9.0
0.9.0.post2
0.9.0.post3
0.9.0.post4
0.9.0.post5
0.9.1
0.9.1.post0
0.9.1.post1
0.9.1.post2
1.0.0
1.0.0.post0
1.0.0.post1
1.0.0.post2
1.0.0.post3
1.0.1
1.0.2
1.0.2.post0
1.1.0
1.1.0rc0
1.1.1
1.10.0
1.10.0.post0
1.10.1
1.11.0
1.12.0
1.12.0.post0
1.12.1
1.13.0
1.13.1
1.14.0
1.14.0.post0
1.15.0
1.2
1.3
1.3.post0
1.3.post1
1.4
1.4.1
1.4.1.post0
1.4.1.post1
1.5.0
1.5.0.post0
1.6.0
1.7.0
1.7.1
1.7.2
1.7.3
1.8.0
1.8.1
1.8.2
1.8.2.post0
1.8.2.post1
1.9.0
1.9.1
1.9.1.post0
1.9.2
1.9.2.post0
Fixed in
1.16.0
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-47783
GHSA-8jhr-wpcm-hh4h
PYSEC-2025-124
May 15, 2025
label-studio vulnerable to Cross-Site Scripting (Reflected) via the label_config parameter.
High
Network
Low
None
SummaryThe vulnerability allows an attacker to inject a malicious script into the context of a web page, which can lead to data theft, unauthorized actions on behalf of the user, and other attacks. DetailsThe vulnerability is reproducible when sending a properly formatted request to the
The vulnerability is specifically located in line 57, where HttpResponse is used.
PoCSend the following request after changing the
Or you can create a vulnerable HTML page by changing
Impact
Affected versions
0.4.1
0.4.2
0.4.3
0.4.4
0.4.4.post1
0.4.4.post2
0.4.5
0.4.6
0.4.6.post1
0.4.6.post2
0.4.7
0.4.8
+ 78 more Show less
0.5.0
0.5.1
0.6.0
0.6.1
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.4.post0
0.7.4.post1
0.7.5.post1
0.7.5.post2
0.8.0
0.8.0.post0
0.8.1
0.8.1.post0
0.8.2
0.8.2.post0
0.9.0
0.9.0.post2
0.9.0.post3
0.9.0.post4
0.9.0.post5
0.9.1
0.9.1.post0
0.9.1.post1
0.9.1.post2
1.0.0
1.0.0.post0
1.0.0.post1
1.0.0.post2
1.0.0.post3
1.0.1
1.0.2
1.0.2.post0
1.1.0
1.1.0rc0
1.1.1
1.10.0
1.10.0.post0
1.10.1
1.11.0
1.12.0
1.12.0.post0
1.12.1
1.13.0
1.13.1
1.14.0
1.14.0.post0
1.15.0
1.16.0
1.17.0
1.2
1.3
1.3.post0
1.3.post1
1.4
1.4.1
1.4.1.post0
1.4.1.post1
1.5.0
1.5.0.post0
1.6.0
1.7.0
1.7.1
1.7.2
1.7.3
1.8.0
1.8.1
1.8.2
1.8.2.post0
1.8.2.post1
1.9.0
1.9.1
1.9.1.post0
1.9.2
1.9.2.post0
Fixed in
1.18.0
References
Updated Jun 06, 2026 · Source: OSV.dev
CVE-2024-26152
PYSEC-2024-249
GHSA-6xv9-957j-qfhg
Feb 22, 2024
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
SummaryOn all Label Studio versions prior to 1.11.0, data imported via file upload feature is not properly sanitized prior to being rendered within a DetailsNeed permission to use the "data import" function. This was reproduced on Label Studio 1.10.1. PoC
The following are the contents of the files used in the PoC
ImpactMalicious scripts can be injected into the code, and when linked with vulnerabilities such as CSRF, it can cause even greater damage. In particular, It can become a source of further attacks, especially when linked to social engineering. Affected versions
0.4.1
0.4.2
0.4.3
0.4.4
0.4.4.post1
0.4.4.post2
0.4.5
0.4.6
0.4.6.post1
0.4.6.post2
0.4.7
0.4.8
+ 113 more Show less
0.5.0
0.5.1
0.6.0
0.6.1
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.4.post0
0.7.4.post1
0.7.5.post1
0.7.5.post2
0.8.0
0.8.0.post0
0.8.1
0.8.1.post0
0.8.2
0.8.2.post0
0.9.0
0.9.0.post2
0.9.0.post3
0.9.0.post4
0.9.0.post5
0.9.1
0.9.1.post0
0.9.1.post1
0.9.1.post2
1.0.0
1.0.0.post0
1.0.0.post1
1.0.0.post2
1.0.0.post3
1.0.1
1.0.2
1.0.2.post0
1.1.0
1.1.0rc0
1.1.1
1.10.0
1.10.0.post0
1.10.1
1.2
1.3
1.3.post0
1.3.post1
1.4
1.4.1
1.4.1.post0
1.4.1.post1
1.5.0
1.5.0.post0
1.6.0
1.7.0
1.7.1
1.7.2
1.7.3
1.8.0
1.8.1
1.8.2
1.8.2.post0
1.8.2.post1
1.9.0
1.9.1
1.9.1.post0
1.9.2
1.9.2.post0
v1.4.1
v1.4.0
v1.3.0
v1.2.0
v1.1.1
v1.1.0
v1.0.2
v1.0.1
v1.0.0
v0.9.1.post1
v0.9.1.post0
v0.9.0.post5
v0.9.0.post4
v0.9.0.post3
v0.9.0
v0.8.2
v0.8.1
v0.8.0
v0.7.5.post0
v0.7.3
v0.7.2
v0.7.1
v0.7.0
v0.6.1
v0.6.0
v0.5.1
v0.4.8
v0.4.7
v0.4.6
v0.4.5
v0.4.4
v0.4.0
v0.3.0
v0.2.2
v.0.2.1-8
v.0.2.1-5
v.0.2.1-4
v.0.2.1-3
v.0.2.1-2
v.0.2.0
v.0.1.6
v.0.1.5
v.0.1.4
v.0.1.2
v.0.1.1
v.0.1.0
Fixed in
1.11.0
References
Updated Jun 10, 2026 · Source: OSV.dev
CVE-2023-47116
GHSA-p59w-9gqw-wj8r
PYSEC-2024-127
Jan 31, 2024
Label Studio SSRF on Import Bypassing `SSRF_PROTECTION_ENABLED` Protections
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
IntroductionThis write-up describes a vulnerability found in Label Studio, a popular open source data labeling tool. The vulnerability affects all versions of Label Studio prior to OverviewLabel Studio's SSRF protections that can be enabled by setting the DescriptionThe following
The
The issue here is the SSRF validation is only performed before the request is sent, and does not validate the destination IP address. Therefore, an attacker can either redirect the request or perform a DNS rebinding attack to bypass this protection. Proof of ConceptBoth the HTTP redirection and DNS rebinding methods for bypassing Label Studio's SSRF protections are explained below. HTTP RedirectionThe python
DNS Rebinding AttackDNS rebinding can bypass SSRF protections by resolving to an external IP address for the first resolution, but when the request is sent resolves to an internal IP address that is blocked. For an example, the domain ImpactSSRF vulnerabilities pose a significant risk on cloud environments, since instance credentials are managed by internal web APIs. An attacker can bypass Label Studio's SSRF protections to access internal web servers and partially compromise the confidentiality of those internal servers. Remediation Advice
Discovered
Affected versions
0.4.1
0.4.2
0.4.3
0.4.4
0.4.4.post1
0.4.4.post2
0.4.5
0.4.6
0.4.6.post1
0.4.6.post2
0.4.7
0.4.8
+ 67 more Show less
0.5.0
0.5.1
0.6.0
0.6.1
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.4.post0
0.7.4.post1
0.7.5.post1
0.7.5.post2
0.8.0
0.8.0.post0
0.8.1
0.8.1.post0
0.8.2
0.8.2.post0
0.9.0
0.9.0.post2
0.9.0.post3
0.9.0.post4
0.9.0.post5
0.9.1
0.9.1.post0
0.9.1.post1
0.9.1.post2
1.0.0
1.0.0.post0
1.0.0.post1
1.0.0.post2
1.0.0.post3
1.0.1
1.0.2
1.0.2.post0
1.1.0
1.1.0rc0
1.1.1
1.10.0
1.10.0.post0
1.10.1
1.2
1.3
1.3.post0
1.3.post1
1.4
1.4.1
1.4.1.post0
1.4.1.post1
1.5.0
1.5.0.post0
1.6.0
1.7.0
1.7.1
1.7.2
1.7.3
1.8.0
1.8.1
1.8.2
1.8.2.post0
1.8.2.post1
1.9.0
1.9.1
1.9.1.post0
1.9.2
1.9.2.post0
Fixed in
1.11.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-23633
GHSA-fq23-g58m-799r
PYSEC-2024-128
Jan 24, 2024
Cross-site Scripting Vulnerability on Data Import
4.7
/ 10
Medium
Network
Low
None
Required
Changed
Low
None
None
IntroductionThis write-up describes a vulnerability found in Label Studio, a popular open source data labeling tool. The vulnerability affects all versions of Label Studio prior to OverviewLabel Studio had a remote import feature allowed users to import data from a remote web source, that was downloaded and could be viewed on the website. This feature could had been abused to download a HTML file that executed malicious JavaScript code in the context of the Label Studio website. DescriptionThe following code snippet in Label Studio showed that is a URL passed the SSRF verification checks, the contents of the file would be downloaded using the filename in the URL.
The downloaded file path could then be retrieved by sending a request to
Since the Proof of ConceptBelow were the steps to recreate this issue:
ImpactExecuting arbitrary JavaScript could result in an attacker performing malicious actions on Label Studio users if they visit the crafted avatar image. For an example, an attacker can craft a JavaScript payload that adds a new Django Super Administrator user if a Django administrator visits the image. Remediation Advice
Discovered
Affected versions
0.4.1
0.4.2
0.4.3
0.4.4
0.4.4.post1
0.4.4.post2
0.4.5
0.4.6
0.4.6.post1
0.4.6.post2
0.4.7
0.4.8
+ 66 more Show less
0.5.0
0.5.1
0.6.0
0.6.1
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.4.post0
0.7.4.post1
0.7.5.post1
0.7.5.post2
0.8.0
0.8.0.post0
0.8.1
0.8.1.post0
0.8.2
0.8.2.post0
0.9.0
0.9.0.post2
0.9.0.post3
0.9.0.post4
0.9.0.post5
0.9.1
0.9.1.post0
0.9.1.post1
0.9.1.post2
1.0.0
1.0.0.post0
1.0.0.post1
1.0.0.post2
1.0.0.post3
1.0.1
1.0.2
1.0.2.post0
1.1.0
1.1.0rc0
1.1.1
1.10.0
1.10.0.post0
1.2
1.3
1.3.post0
1.3.post1
1.4
1.4.1
1.4.1.post0
1.4.1.post1
1.5.0
1.5.0.post0
1.6.0
1.7.0
1.7.1
1.7.2
1.7.3
1.8.0
1.8.1
1.8.2
1.8.2.post0
1.8.2.post1
1.9.0
1.9.1
1.9.1.post0
1.9.2
1.9.2.post0
Fixed in
1.10.1
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2023-47115
GHSA-q68h-xwq5-mm7x
PYSEC-2024-126
Jan 24, 2024
Cross-site Scripting Vulnerability on Avatar Upload
7.1
/ 10
High
Network
Low
None
Required
Changed
Low
Low
Low
IntroductionThis write-up describes a vulnerability found in Label Studio, a popular open source data labeling tool. The vulnerability affects all versions of Label Studio prior to OverviewLabel Studio has a cross-site scripting (XSS) vulnerability that could be exploited when an authenticated user uploads a crafted image file for their avatar that gets rendered as a HTML file on the website. DescriptionThe following code snippet in Label Studio shows that the only verification check is that the file is an image by extracting the dimensions from the file.
Label Studio serves avatar images using Django's built-in
The issue with the Django Proof of ConceptBelow are the steps to reproduce this issue and execute JavaScript code in the context of the Label Studio website.
ImpactExecuting arbitrary JavaScript could result in an attacker performing malicious actions on Label Studio users if they visit the crafted avatar image. For an example, an attacker can craft a JavaScript payload that adds a new Django Super Administrator user if a Django administrator visits the image. Remediation Advice
Discovered
Affected versions
0.4.1
0.4.2
0.4.3
0.4.4
0.4.4.post1
0.4.4.post2
0.4.5
0.4.6
0.4.6.post1
0.4.6.post2
0.4.7
0.4.8
+ 62 more Show less
0.5.0
0.5.1
0.6.0
0.6.1
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.4.post0
0.7.4.post1
0.7.5.post1
0.7.5.post2
0.8.0
0.8.0.post0
0.8.1
0.8.1.post0
0.8.2
0.8.2.post0
0.9.0
0.9.0.post2
0.9.0.post3
0.9.0.post4
0.9.0.post5
0.9.1
0.9.1.post0
0.9.1.post1
0.9.1.post2
1.0.0
1.0.0.post0
1.0.0.post1
1.0.0.post2
1.0.0.post3
1.0.1
1.0.2
1.0.2.post0
1.1.0
1.1.0rc0
1.1.1
1.2
1.3
1.3.post0
1.3.post1
1.4
1.4.1
1.4.1.post0
1.4.1.post1
1.5.0
1.5.0.post0
1.6.0
1.7.0
1.7.1
1.7.2
1.7.3
1.8.0
1.8.1
1.8.2
1.8.2.post0
1.8.2.post1
1.9.0
1.9.1
1.9.1.post0
Fixed in
1.9.2
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2023-47117
GHSA-6hjj-gq77-j4qw
PYSEC-2023-275
Nov 14, 2023
Label Studio Object Relational Mapper Leak Vulnerability in Filtering Task
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
IntroductionThis write-up describes a vulnerability found in Label Studio, a popular open source data labeling tool. The vulnerability affects all versions of Label Studio prior to OverviewIn all current versions of Label Studio, the application allows users to insecurely set filters for filtering tasks. An attacker can construct a filter chain to filter tasks based on sensitive fields for all user accounts on the platform by exploiting Django's Object Relational Mapper (ORM). Since the results of query can be manipulated by the ORM filter, an attacker can leak these sensitive fields character by character. For an example, the following filter chain will task results by the password hash of an account on Label Studio.
For consistency, this type of vulnerability will be termed as ORM Leak in the rest of this disclosure. In addition, Label Studio had a hard coded secret key that an attacker can use to forge a session token of any user by exploiting this ORM Leak vulnerability to leak account password hashes. DescriptionThe following code snippet from the
These
The
The following code snippet of the
Finally, the
Proof of ConceptBelow are the steps to exploit about how to exploit this vulnerability to leak the password hash of an account on Label Studio.
The following example GIF demonstrates exploiting this ORM Leak vulnerability to retrieve the password hash
ImpactThis vulnerability can be exploited to completely compromise the confidentiality of highly sensitive account information, such as account password hashes. For all versions Remediation Advice
Discovered
| ||
1.4
minor
12 CVEs
CVE-2026-22033
PYSEC-2026-1502
GHSA-2mq9-hm29-8qch
Jul 07, 2026
Label Studio is vulnerable to full account takeover by chaining Stored XSS + IDOR in User Profile via custom_hotkeys field
Critical
Network
Low
Low
None
PrologueThese vulnerabilities have been found and chained by DCODX-AI. Validation of the exploit chain has been confirmed manually. SummaryA persistent stored cross-site scripting (XSS) vulnerability exists in the custom_hotkeys functionality of the application. An authenticated attacker (or one who can trick a user/administrator into updating their custom_hotkeys) can inject JavaScript code that executes in other users’ browsers when those users load any page using the DetailsWithin
Here, user.custom_hotkeys is run through json_dumps_ensure_ascii (in In
The serializer allows
When another user loads a page using templates/base.html (for example PoC
Example request
Example response
ImpactExploitation impact:
Who is impacted:
Affected versions
0.4.1
0.4.2
0.4.3
0.4.4
0.4.4.post1
0.4.4.post2
0.4.5
0.4.6
0.4.6.post1
0.4.6.post2
0.4.7
0.4.8
+ 83 more Show less
0.5.0
0.5.1
0.6.0
0.6.1
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.4.post0
0.7.4.post1
0.7.5.post1
0.7.5.post2
0.8.0
0.8.0.post0
0.8.1
0.8.1.post0
0.8.2
0.8.2.post0
0.9.0
0.9.0.post2
0.9.0.post3
0.9.0.post4
0.9.0.post5
0.9.1
0.9.1.post0
0.9.1.post1
0.9.1.post2
1.0.0
1.0.0.post0
1.0.0.post1
1.0.0.post2
1.0.0.post3
1.0.1
1.0.2
1.0.2.post0
1.1.0
1.1.0rc0
1.1.1
1.10.0
1.10.0.post0
1.10.1
1.11.0
1.12.0
1.12.0.post0
1.12.1
1.13.0
1.13.1
1.14.0
1.14.0.post0
1.15.0
1.16.0
1.17.0
1.18.0
1.19.0
1.2
1.20.0
1.21.0
1.22.0
1.3
1.3.post0
1.3.post1
1.4
1.4.1
1.4.1.post0
1.4.1.post1
1.5.0
1.5.0.post0
1.6.0
1.7.0
1.7.1
1.7.2
1.7.3
1.8.0
1.8.1
1.8.2
1.8.2.post0
1.8.2.post1
1.9.0
1.9.1
1.9.1.post0
1.9.2
1.9.2.post0
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-25297
PYSEC-2026-1503
GHSA-m238-fmcw-wh58
Jul 07, 2026
Label Studio allows Server-Side Request Forgery in the S3 Storage Endpoint
8.6
/ 10
High
Network
Low
None
None
Changed
High
None
None
DescriptionLabel Studio's S3 storage integration feature contains a Server-Side Request Forgery (SSRF) vulnerability in its endpoint configuration. When creating an S3 storage connection, the application allows users to specify a custom S3 endpoint URL via the s3_endpoint parameter. This endpoint URL is passed directly to the boto3 AWS SDK without proper validation or restrictions on the protocol or destination. The vulnerability allows an attacker to make the application send HTTP requests to arbitrary internal services by specifying them as the S3 endpoint. When the storage sync operation is triggered, the application attempts to make S3 API calls to the specified endpoint, effectively making HTTP requests to the target service and returning the response in error messages. This SSRF vulnerability enables attackers to bypass network segmentation and access internal services that should not be accessible from the external network. The vulnerability is particularly severe because error messages from failed requests contain the full response body, allowing data exfiltration from internal services. Steps to reproduce
The application will attempt to connect to the specified endpoint URL as if it were an S3 service. When the request fails due to invalid S3 API responses, the error message will contain the raw response from the internal service, allowing access to internal resources. Mitigations
ImpactThis vulnerability has high severity as it allows authenticated users to make requests to arbitrary internal services from the application server, potentially exposing sensitive internal resources and bypassing network segmentation. The inclusion of response data in error messages makes this particularly effective for data exfiltration. Affected versions
0.4.1
0.4.2
0.4.3
0.4.4
0.4.4.post1
0.4.4.post2
0.4.5
0.4.6
0.4.6.post1
0.4.6.post2
0.4.7
0.4.8
+ 76 more Show less
0.5.0
0.5.1
0.6.0
0.6.1
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.4.post0
0.7.4.post1
0.7.5.post1
0.7.5.post2
0.8.0
0.8.0.post0
0.8.1
0.8.1.post0
0.8.2
0.8.2.post0
0.9.0
0.9.0.post2
0.9.0.post3
0.9.0.post4
0.9.0.post5
0.9.1
0.9.1.post0
0.9.1.post1
0.9.1.post2
1.0.0
1.0.0.post0
1.0.0.post1
1.0.0.post2
1.0.0.post3
1.0.1
1.0.2
1.0.2.post0
1.1.0
1.1.0rc0
1.1.1
1.10.0
1.10.0.post0
1.10.1
1.11.0
1.12.0
1.12.0.post0
1.12.1
1.13.0
1.13.1
1.14.0
1.14.0.post0
1.15.0
1.2
1.3
1.3.post0
1.3.post1
1.4
1.4.1
1.4.1.post0
1.4.1.post1
1.5.0
1.5.0.post0
1.6.0
1.7.0
1.7.1
1.7.2
1.7.3
1.8.0
1.8.1
1.8.2
1.8.2.post0
1.8.2.post1
1.9.0
1.9.1
1.9.1.post0
1.9.2
1.9.2.post0
Fixed in
1.16.0
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-25296
PYSEC-2026-1504
GHSA-wpq5-3366-mqw4
Jul 07, 2026
Label Studio allows Cross-Site Scripting (XSS) via GET request to `/projects/upload-example` endpoint
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
DescriptionLabel Studio's The vulnerability exists because the upload-example endpoint renders user-provided HTML content without proper sanitization on a GET request. This allows attackers to inject and execute arbitrary JavaScript in victims' browsers by getting them to visit a maliciously crafted URL. This is considered vulnerable because it enables attackers to execute JavaScript in victims' contexts, potentially allowing theft of sensitive data, session hijacking, or other malicious actions. Steps to reproduce
When executed, the payload causes the application to render an HTML page containing an img tag that fails to load, triggering the onerror event handler which executes base64-decoded JavaScript, demonstrating successful XSS execution in the victim's browser. Mitigations
ImpactThe vulnerability requires no special privileges and can be exploited by getting a victim to visit a crafted URL. The impact is high as it allows arbitrary JavaScript execution in victims' browsers, potentially exposing sensitive data or enabling account takeover through session theft. Affected versions
0.4.1
0.4.2
0.4.3
0.4.4
0.4.4.post1
0.4.4.post2
0.4.5
0.4.6
0.4.6.post1
0.4.6.post2
0.4.7
0.4.8
+ 76 more Show less
0.5.0
0.5.1
0.6.0
0.6.1
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.4.post0
0.7.4.post1
0.7.5.post1
0.7.5.post2
0.8.0
0.8.0.post0
0.8.1
0.8.1.post0
0.8.2
0.8.2.post0
0.9.0
0.9.0.post2
0.9.0.post3
0.9.0.post4
0.9.0.post5
0.9.1
0.9.1.post0
0.9.1.post1
0.9.1.post2
1.0.0
1.0.0.post0
1.0.0.post1
1.0.0.post2
1.0.0.post3
1.0.1
1.0.2
1.0.2.post0
1.1.0
1.1.0rc0
1.1.1
1.10.0
1.10.0.post0
1.10.1
1.11.0
1.12.0
1.12.0.post0
1.12.1
1.13.0
1.13.1
1.14.0
1.14.0.post0
1.15.0
1.2
1.3
1.3.post0
1.3.post1
1.4
1.4.1
1.4.1.post0
1.4.1.post1
1.5.0
1.5.0.post0
1.6.0
1.7.0
1.7.1
1.7.2
1.7.3
1.8.0
1.8.1
1.8.2
1.8.2.post0
1.8.2.post1
1.9.0
1.9.1
1.9.1.post0
1.9.2
1.9.2.post0
Fixed in
1.16.0
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-47783
GHSA-8jhr-wpcm-hh4h
PYSEC-2025-124
May 15, 2025
label-studio vulnerable to Cross-Site Scripting (Reflected) via the label_config parameter.
High
Network
Low
None
SummaryThe vulnerability allows an attacker to inject a malicious script into the context of a web page, which can lead to data theft, unauthorized actions on behalf of the user, and other attacks. DetailsThe vulnerability is reproducible when sending a properly formatted request to the
The vulnerability is specifically located in line 57, where HttpResponse is used.
PoCSend the following request after changing the
Or you can create a vulnerable HTML page by changing
Impact
Affected versions
0.4.1
0.4.2
0.4.3
0.4.4
0.4.4.post1
0.4.4.post2
0.4.5
0.4.6
0.4.6.post1
0.4.6.post2
0.4.7
0.4.8
+ 78 more Show less
0.5.0
0.5.1
0.6.0
0.6.1
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.4.post0
0.7.4.post1
0.7.5.post1
0.7.5.post2
0.8.0
0.8.0.post0
0.8.1
0.8.1.post0
0.8.2
0.8.2.post0
0.9.0
0.9.0.post2
0.9.0.post3
0.9.0.post4
0.9.0.post5
0.9.1
0.9.1.post0
0.9.1.post1
0.9.1.post2
1.0.0
1.0.0.post0
1.0.0.post1
1.0.0.post2
1.0.0.post3
1.0.1
1.0.2
1.0.2.post0
1.1.0
1.1.0rc0
1.1.1
1.10.0
1.10.0.post0
1.10.1
1.11.0
1.12.0
1.12.0.post0
1.12.1
1.13.0
1.13.1
1.14.0
1.14.0.post0
1.15.0
1.16.0
1.17.0
1.2
1.3
1.3.post0
1.3.post1
1.4
1.4.1
1.4.1.post0
1.4.1.post1
1.5.0
1.5.0.post0
1.6.0
1.7.0
1.7.1
1.7.2
1.7.3
1.8.0
1.8.1
1.8.2
1.8.2.post0
1.8.2.post1
1.9.0
1.9.1
1.9.1.post0
1.9.2
1.9.2.post0
Fixed in
1.18.0
References
Updated Jun 06, 2026 · Source: OSV.dev
CVE-2024-26152
PYSEC-2024-249
GHSA-6xv9-957j-qfhg
Feb 22, 2024
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
SummaryOn all Label Studio versions prior to 1.11.0, data imported via file upload feature is not properly sanitized prior to being rendered within a DetailsNeed permission to use the "data import" function. This was reproduced on Label Studio 1.10.1. PoC
The following are the contents of the files used in the PoC
ImpactMalicious scripts can be injected into the code, and when linked with vulnerabilities such as CSRF, it can cause even greater damage. In particular, It can become a source of further attacks, especially when linked to social engineering. Affected versions
0.4.1
0.4.2
0.4.3
0.4.4
0.4.4.post1
0.4.4.post2
0.4.5
0.4.6
0.4.6.post1
0.4.6.post2
0.4.7
0.4.8
+ 113 more Show less
0.5.0
0.5.1
0.6.0
0.6.1
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.4.post0
0.7.4.post1
0.7.5.post1
0.7.5.post2
0.8.0
0.8.0.post0
0.8.1
0.8.1.post0
0.8.2
0.8.2.post0
0.9.0
0.9.0.post2
0.9.0.post3
0.9.0.post4
0.9.0.post5
0.9.1
0.9.1.post0
0.9.1.post1
0.9.1.post2
1.0.0
1.0.0.post0
1.0.0.post1
1.0.0.post2
1.0.0.post3
1.0.1
1.0.2
1.0.2.post0
1.1.0
1.1.0rc0
1.1.1
1.10.0
1.10.0.post0
1.10.1
1.2
1.3
1.3.post0
1.3.post1
1.4
1.4.1
1.4.1.post0
1.4.1.post1
1.5.0
1.5.0.post0
1.6.0
1.7.0
1.7.1
1.7.2
1.7.3
1.8.0
1.8.1
1.8.2
1.8.2.post0
1.8.2.post1
1.9.0
1.9.1
1.9.1.post0
1.9.2
1.9.2.post0
v1.4.1
v1.4.0
v1.3.0
v1.2.0
v1.1.1
v1.1.0
v1.0.2
v1.0.1
v1.0.0
v0.9.1.post1
v0.9.1.post0
v0.9.0.post5
v0.9.0.post4
v0.9.0.post3
v0.9.0
v0.8.2
v0.8.1
v0.8.0
v0.7.5.post0
v0.7.3
v0.7.2
v0.7.1
v0.7.0
v0.6.1
v0.6.0
v0.5.1
v0.4.8
v0.4.7
v0.4.6
v0.4.5
v0.4.4
v0.4.0
v0.3.0
v0.2.2
v.0.2.1-8
v.0.2.1-5
v.0.2.1-4
v.0.2.1-3
v.0.2.1-2
v.0.2.0
v.0.1.6
v.0.1.5
v.0.1.4
v.0.1.2
v.0.1.1
v.0.1.0
Fixed in
1.11.0
References
Updated Jun 10, 2026 · Source: OSV.dev
CVE-2023-47116
GHSA-p59w-9gqw-wj8r
PYSEC-2024-127
Jan 31, 2024
Label Studio SSRF on Import Bypassing `SSRF_PROTECTION_ENABLED` Protections
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
IntroductionThis write-up describes a vulnerability found in Label Studio, a popular open source data labeling tool. The vulnerability affects all versions of Label Studio prior to OverviewLabel Studio's SSRF protections that can be enabled by setting the DescriptionThe following
The
The issue here is the SSRF validation is only performed before the request is sent, and does not validate the destination IP address. Therefore, an attacker can either redirect the request or perform a DNS rebinding attack to bypass this protection. Proof of ConceptBoth the HTTP redirection and DNS rebinding methods for bypassing Label Studio's SSRF protections are explained below. HTTP RedirectionThe python
DNS Rebinding AttackDNS rebinding can bypass SSRF protections by resolving to an external IP address for the first resolution, but when the request is sent resolves to an internal IP address that is blocked. For an example, the domain ImpactSSRF vulnerabilities pose a significant risk on cloud environments, since instance credentials are managed by internal web APIs. An attacker can bypass Label Studio's SSRF protections to access internal web servers and partially compromise the confidentiality of those internal servers. Remediation Advice
Discovered
Affected versions
0.4.1
0.4.2
0.4.3
0.4.4
0.4.4.post1
0.4.4.post2
0.4.5
0.4.6
0.4.6.post1
0.4.6.post2
0.4.7
0.4.8
+ 67 more Show less
0.5.0
0.5.1
0.6.0
0.6.1
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.4.post0
0.7.4.post1
0.7.5.post1
0.7.5.post2
0.8.0
0.8.0.post0
0.8.1
0.8.1.post0
0.8.2
0.8.2.post0
0.9.0
0.9.0.post2
0.9.0.post3
0.9.0.post4
0.9.0.post5
0.9.1
0.9.1.post0
0.9.1.post1
0.9.1.post2
1.0.0
1.0.0.post0
1.0.0.post1
1.0.0.post2
1.0.0.post3
1.0.1
1.0.2
1.0.2.post0
1.1.0
1.1.0rc0
1.1.1
1.10.0
1.10.0.post0
1.10.1
1.2
1.3
1.3.post0
1.3.post1
1.4
1.4.1
1.4.1.post0
1.4.1.post1
1.5.0
1.5.0.post0
1.6.0
1.7.0
1.7.1
1.7.2
1.7.3
1.8.0
1.8.1
1.8.2
1.8.2.post0
1.8.2.post1
1.9.0
1.9.1
1.9.1.post0
1.9.2
1.9.2.post0
Fixed in
1.11.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-23633
GHSA-fq23-g58m-799r
PYSEC-2024-128
Jan 24, 2024
Cross-site Scripting Vulnerability on Data Import
4.7
/ 10
Medium
Network
Low
None
Required
Changed
Low
None
None
IntroductionThis write-up describes a vulnerability found in Label Studio, a popular open source data labeling tool. The vulnerability affects all versions of Label Studio prior to OverviewLabel Studio had a remote import feature allowed users to import data from a remote web source, that was downloaded and could be viewed on the website. This feature could had been abused to download a HTML file that executed malicious JavaScript code in the context of the Label Studio website. DescriptionThe following code snippet in Label Studio showed that is a URL passed the SSRF verification checks, the contents of the file would be downloaded using the filename in the URL.
The downloaded file path could then be retrieved by sending a request to
Since the Proof of ConceptBelow were the steps to recreate this issue:
ImpactExecuting arbitrary JavaScript could result in an attacker performing malicious actions on Label Studio users if they visit the crafted avatar image. For an example, an attacker can craft a JavaScript payload that adds a new Django Super Administrator user if a Django administrator visits the image. Remediation Advice
Discovered
Affected versions
0.4.1
0.4.2
0.4.3
0.4.4
0.4.4.post1
0.4.4.post2
0.4.5
0.4.6
0.4.6.post1
0.4.6.post2
0.4.7
0.4.8
+ 66 more Show less
0.5.0
0.5.1
0.6.0
0.6.1
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.4.post0
0.7.4.post1
0.7.5.post1
0.7.5.post2
0.8.0
0.8.0.post0
0.8.1
0.8.1.post0
0.8.2
0.8.2.post0
0.9.0
0.9.0.post2
0.9.0.post3
0.9.0.post4
0.9.0.post5
0.9.1
0.9.1.post0
0.9.1.post1
0.9.1.post2
1.0.0
1.0.0.post0
1.0.0.post1
1.0.0.post2
1.0.0.post3
1.0.1
1.0.2
1.0.2.post0
1.1.0
1.1.0rc0
1.1.1
1.10.0
1.10.0.post0
1.2
1.3
1.3.post0
1.3.post1
1.4
1.4.1
1.4.1.post0
1.4.1.post1
1.5.0
1.5.0.post0
1.6.0
1.7.0
1.7.1
1.7.2
1.7.3
1.8.0
1.8.1
1.8.2
1.8.2.post0
1.8.2.post1
1.9.0
1.9.1
1.9.1.post0
1.9.2
1.9.2.post0
Fixed in
1.10.1
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2023-47115
GHSA-q68h-xwq5-mm7x
PYSEC-2024-126
Jan 24, 2024
Cross-site Scripting Vulnerability on Avatar Upload
7.1
/ 10
High
Network
Low
None
Required
Changed
Low
Low
Low
IntroductionThis write-up describes a vulnerability found in Label Studio, a popular open source data labeling tool. The vulnerability affects all versions of Label Studio prior to OverviewLabel Studio has a cross-site scripting (XSS) vulnerability that could be exploited when an authenticated user uploads a crafted image file for their avatar that gets rendered as a HTML file on the website. DescriptionThe following code snippet in Label Studio shows that the only verification check is that the file is an image by extracting the dimensions from the file.
Label Studio serves avatar images using Django's built-in
The issue with the Django Proof of ConceptBelow are the steps to reproduce this issue and execute JavaScript code in the context of the Label Studio website.
ImpactExecuting arbitrary JavaScript could result in an attacker performing malicious actions on Label Studio users if they visit the crafted avatar image. For an example, an attacker can craft a JavaScript payload that adds a new Django Super Administrator user if a Django administrator visits the image. Remediation Advice
Discovered
Affected versions
0.4.1
0.4.2
0.4.3
0.4.4
0.4.4.post1
0.4.4.post2
0.4.5
0.4.6
0.4.6.post1
0.4.6.post2
0.4.7
0.4.8
+ 62 more Show less
0.5.0
0.5.1
0.6.0
0.6.1
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.4.post0
0.7.4.post1
0.7.5.post1
0.7.5.post2
0.8.0
0.8.0.post0
0.8.1
0.8.1.post0
0.8.2
0.8.2.post0
0.9.0
0.9.0.post2
0.9.0.post3
0.9.0.post4
0.9.0.post5
0.9.1
0.9.1.post0
0.9.1.post1
0.9.1.post2
1.0.0
1.0.0.post0
1.0.0.post1
1.0.0.post2
1.0.0.post3
1.0.1
1.0.2
1.0.2.post0
1.1.0
1.1.0rc0
1.1.1
1.2
1.3
1.3.post0
1.3.post1
1.4
1.4.1
1.4.1.post0
1.4.1.post1
1.5.0
1.5.0.post0
1.6.0
1.7.0
1.7.1
1.7.2
1.7.3
1.8.0
1.8.1
1.8.2
1.8.2.post0
1.8.2.post1
1.9.0
1.9.1
1.9.1.post0
Fixed in
1.9.2
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2023-47117
GHSA-6hjj-gq77-j4qw
PYSEC-2023-275
Nov 14, 2023
Label Studio Object Relational Mapper Leak Vulnerability in Filtering Task
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
IntroductionThis write-up describes a vulnerability found in Label Studio, a popular open source data labeling tool. The vulnerability affects all versions of Label Studio prior to OverviewIn all current versions of Label Studio, the application allows users to insecurely set filters for filtering tasks. An attacker can construct a filter chain to filter tasks based on sensitive fields for all user accounts on the platform by exploiting Django's Object Relational Mapper (ORM). Since the results of query can be manipulated by the ORM filter, an attacker can leak these sensitive fields character by character. For an example, the following filter chain will task results by the password hash of an account on Label Studio.
For consistency, this type of vulnerability will be termed as ORM Leak in the rest of this disclosure. In addition, Label Studio had a hard coded secret key that an attacker can use to forge a session token of any user by exploiting this ORM Leak vulnerability to leak account password hashes. DescriptionThe following code snippet from the
These
The
The following code snippet of the
Finally, the
Proof of ConceptBelow are the steps to exploit about how to exploit this vulnerability to leak the password hash of an account on Label Studio.
The following example GIF demonstrates exploiting this ORM Leak vulnerability to retrieve the password hash
ImpactThis vulnerability can be exploited to completely compromise the confidentiality of highly sensitive account information, such as account password hashes. For all versions Remediation Advice
Discovered
| ||
1.3.post1
pre
12 CVEs
CVE-2026-22033
PYSEC-2026-1502
GHSA-2mq9-hm29-8qch
Jul 07, 2026
Label Studio is vulnerable to full account takeover by chaining Stored XSS + IDOR in User Profile via custom_hotkeys field
Critical
Network
Low
Low
None
PrologueThese vulnerabilities have been found and chained by DCODX-AI. Validation of the exploit chain has been confirmed manually. SummaryA persistent stored cross-site scripting (XSS) vulnerability exists in the custom_hotkeys functionality of the application. An authenticated attacker (or one who can trick a user/administrator into updating their custom_hotkeys) can inject JavaScript code that executes in other users’ browsers when those users load any page using the DetailsWithin
Here, user.custom_hotkeys is run through json_dumps_ensure_ascii (in In
The serializer allows
When another user loads a page using templates/base.html (for example PoC
Example request
Example response
ImpactExploitation impact:
Who is impacted:
Affected versions
0.4.1
0.4.2
0.4.3
0.4.4
0.4.4.post1
0.4.4.post2
0.4.5
0.4.6
0.4.6.post1
0.4.6.post2
0.4.7
0.4.8
+ 83 more Show less
0.5.0
0.5.1
0.6.0
0.6.1
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.4.post0
0.7.4.post1
0.7.5.post1
0.7.5.post2
0.8.0
0.8.0.post0
0.8.1
0.8.1.post0
0.8.2
0.8.2.post0
0.9.0
0.9.0.post2
0.9.0.post3
0.9.0.post4
0.9.0.post5
0.9.1
0.9.1.post0
0.9.1.post1
0.9.1.post2
1.0.0
1.0.0.post0
1.0.0.post1
1.0.0.post2
1.0.0.post3
1.0.1
1.0.2
1.0.2.post0
1.1.0
1.1.0rc0
1.1.1
1.10.0
1.10.0.post0
1.10.1
1.11.0
1.12.0
1.12.0.post0
1.12.1
1.13.0
1.13.1
1.14.0
1.14.0.post0
1.15.0
1.16.0
1.17.0
1.18.0
1.19.0
1.2
1.20.0
1.21.0
1.22.0
1.3
1.3.post0
1.3.post1
1.4
1.4.1
1.4.1.post0
1.4.1.post1
1.5.0
1.5.0.post0
1.6.0
1.7.0
1.7.1
1.7.2
1.7.3
1.8.0
1.8.1
1.8.2
1.8.2.post0
1.8.2.post1
1.9.0
1.9.1
1.9.1.post0
1.9.2
1.9.2.post0
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-25297
PYSEC-2026-1503
GHSA-m238-fmcw-wh58
Jul 07, 2026
Label Studio allows Server-Side Request Forgery in the S3 Storage Endpoint
8.6
/ 10
High
Network
Low
None
None
Changed
High
None
None
DescriptionLabel Studio's S3 storage integration feature contains a Server-Side Request Forgery (SSRF) vulnerability in its endpoint configuration. When creating an S3 storage connection, the application allows users to specify a custom S3 endpoint URL via the s3_endpoint parameter. This endpoint URL is passed directly to the boto3 AWS SDK without proper validation or restrictions on the protocol or destination. The vulnerability allows an attacker to make the application send HTTP requests to arbitrary internal services by specifying them as the S3 endpoint. When the storage sync operation is triggered, the application attempts to make S3 API calls to the specified endpoint, effectively making HTTP requests to the target service and returning the response in error messages. This SSRF vulnerability enables attackers to bypass network segmentation and access internal services that should not be accessible from the external network. The vulnerability is particularly severe because error messages from failed requests contain the full response body, allowing data exfiltration from internal services. Steps to reproduce
The application will attempt to connect to the specified endpoint URL as if it were an S3 service. When the request fails due to invalid S3 API responses, the error message will contain the raw response from the internal service, allowing access to internal resources. Mitigations
ImpactThis vulnerability has high severity as it allows authenticated users to make requests to arbitrary internal services from the application server, potentially exposing sensitive internal resources and bypassing network segmentation. The inclusion of response data in error messages makes this particularly effective for data exfiltration. Affected versions
0.4.1
0.4.2
0.4.3
0.4.4
0.4.4.post1
0.4.4.post2
0.4.5
0.4.6
0.4.6.post1
0.4.6.post2
0.4.7
0.4.8
+ 76 more Show less
0.5.0
0.5.1
0.6.0
0.6.1
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.4.post0
0.7.4.post1
0.7.5.post1
0.7.5.post2
0.8.0
0.8.0.post0
0.8.1
0.8.1.post0
0.8.2
0.8.2.post0
0.9.0
0.9.0.post2
0.9.0.post3
0.9.0.post4
0.9.0.post5
0.9.1
0.9.1.post0
0.9.1.post1
0.9.1.post2
1.0.0
1.0.0.post0
1.0.0.post1
1.0.0.post2
1.0.0.post3
1.0.1
1.0.2
1.0.2.post0
1.1.0
1.1.0rc0
1.1.1
1.10.0
1.10.0.post0
1.10.1
1.11.0
1.12.0
1.12.0.post0
1.12.1
1.13.0
1.13.1
1.14.0
1.14.0.post0
1.15.0
1.2
1.3
1.3.post0
1.3.post1
1.4
1.4.1
1.4.1.post0
1.4.1.post1
1.5.0
1.5.0.post0
1.6.0
1.7.0
1.7.1
1.7.2
1.7.3
1.8.0
1.8.1
1.8.2
1.8.2.post0
1.8.2.post1
1.9.0
1.9.1
1.9.1.post0
1.9.2
1.9.2.post0
Fixed in
1.16.0
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-25296
PYSEC-2026-1504
GHSA-wpq5-3366-mqw4
Jul 07, 2026
Label Studio allows Cross-Site Scripting (XSS) via GET request to `/projects/upload-example` endpoint
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
DescriptionLabel Studio's The vulnerability exists because the upload-example endpoint renders user-provided HTML content without proper sanitization on a GET request. This allows attackers to inject and execute arbitrary JavaScript in victims' browsers by getting them to visit a maliciously crafted URL. This is considered vulnerable because it enables attackers to execute JavaScript in victims' contexts, potentially allowing theft of sensitive data, session hijacking, or other malicious actions. Steps to reproduce
When executed, the payload causes the application to render an HTML page containing an img tag that fails to load, triggering the onerror event handler which executes base64-decoded JavaScript, demonstrating successful XSS execution in the victim's browser. Mitigations
ImpactThe vulnerability requires no special privileges and can be exploited by getting a victim to visit a crafted URL. The impact is high as it allows arbitrary JavaScript execution in victims' browsers, potentially exposing sensitive data or enabling account takeover through session theft. Affected versions
0.4.1
0.4.2
0.4.3
0.4.4
0.4.4.post1
0.4.4.post2
0.4.5
0.4.6
0.4.6.post1
0.4.6.post2
0.4.7
0.4.8
+ 76 more Show less
0.5.0
0.5.1
0.6.0
0.6.1
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.4.post0
0.7.4.post1
0.7.5.post1
0.7.5.post2
0.8.0
0.8.0.post0
0.8.1
0.8.1.post0
0.8.2
0.8.2.post0
0.9.0
0.9.0.post2
0.9.0.post3
0.9.0.post4
0.9.0.post5
0.9.1
0.9.1.post0
0.9.1.post1
0.9.1.post2
1.0.0
1.0.0.post0
1.0.0.post1
1.0.0.post2
1.0.0.post3
1.0.1
1.0.2
1.0.2.post0
1.1.0
1.1.0rc0
1.1.1
1.10.0
1.10.0.post0
1.10.1
1.11.0
1.12.0
1.12.0.post0
1.12.1
1.13.0
1.13.1
1.14.0
1.14.0.post0
1.15.0
1.2
1.3
1.3.post0
1.3.post1
1.4
1.4.1
1.4.1.post0
1.4.1.post1
1.5.0
1.5.0.post0
1.6.0
1.7.0
1.7.1
1.7.2
1.7.3
1.8.0
1.8.1
1.8.2
1.8.2.post0
1.8.2.post1
1.9.0
1.9.1
1.9.1.post0
1.9.2
1.9.2.post0
Fixed in
1.16.0
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-47783
GHSA-8jhr-wpcm-hh4h
PYSEC-2025-124
May 15, 2025
label-studio vulnerable to Cross-Site Scripting (Reflected) via the label_config parameter.
High
Network
Low
None
SummaryThe vulnerability allows an attacker to inject a malicious script into the context of a web page, which can lead to data theft, unauthorized actions on behalf of the user, and other attacks. DetailsThe vulnerability is reproducible when sending a properly formatted request to the
The vulnerability is specifically located in line 57, where HttpResponse is used.
PoCSend the following request after changing the
Or you can create a vulnerable HTML page by changing
Impact
Affected versions
0.4.1
0.4.2
0.4.3
0.4.4
0.4.4.post1
0.4.4.post2
0.4.5
0.4.6
0.4.6.post1
0.4.6.post2
0.4.7
0.4.8
+ 78 more Show less
0.5.0
0.5.1
0.6.0
0.6.1
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.4.post0
0.7.4.post1
0.7.5.post1
0.7.5.post2
0.8.0
0.8.0.post0
0.8.1
0.8.1.post0
0.8.2
0.8.2.post0
0.9.0
0.9.0.post2
0.9.0.post3
0.9.0.post4
0.9.0.post5
0.9.1
0.9.1.post0
0.9.1.post1
0.9.1.post2
1.0.0
1.0.0.post0
1.0.0.post1
1.0.0.post2
1.0.0.post3
1.0.1
1.0.2
1.0.2.post0
1.1.0
1.1.0rc0
1.1.1
1.10.0
1.10.0.post0
1.10.1
1.11.0
1.12.0
1.12.0.post0
1.12.1
1.13.0
1.13.1
1.14.0
1.14.0.post0
1.15.0
1.16.0
1.17.0
1.2
1.3
1.3.post0
1.3.post1
1.4
1.4.1
1.4.1.post0
1.4.1.post1
1.5.0
1.5.0.post0
1.6.0
1.7.0
1.7.1
1.7.2
1.7.3
1.8.0
1.8.1
1.8.2
1.8.2.post0
1.8.2.post1
1.9.0
1.9.1
1.9.1.post0
1.9.2
1.9.2.post0
Fixed in
1.18.0
References
Updated Jun 06, 2026 · Source: OSV.dev
CVE-2024-26152
PYSEC-2024-249
GHSA-6xv9-957j-qfhg
Feb 22, 2024
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
SummaryOn all Label Studio versions prior to 1.11.0, data imported via file upload feature is not properly sanitized prior to being rendered within a DetailsNeed permission to use the "data import" function. This was reproduced on Label Studio 1.10.1. PoC
The following are the contents of the files used in the PoC
ImpactMalicious scripts can be injected into the code, and when linked with vulnerabilities such as CSRF, it can cause even greater damage. In particular, It can become a source of further attacks, especially when linked to social engineering. Affected versions
0.4.1
0.4.2
0.4.3
0.4.4
0.4.4.post1
0.4.4.post2
0.4.5
0.4.6
0.4.6.post1
0.4.6.post2
0.4.7
0.4.8
+ 113 more Show less
0.5.0
0.5.1
0.6.0
0.6.1
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.4.post0
0.7.4.post1
0.7.5.post1
0.7.5.post2
0.8.0
0.8.0.post0
0.8.1
0.8.1.post0
0.8.2
0.8.2.post0
0.9.0
0.9.0.post2
0.9.0.post3
0.9.0.post4
0.9.0.post5
0.9.1
0.9.1.post0
0.9.1.post1
0.9.1.post2
1.0.0
1.0.0.post0
1.0.0.post1
1.0.0.post2
1.0.0.post3
1.0.1
1.0.2
1.0.2.post0
1.1.0
1.1.0rc0
1.1.1
1.10.0
1.10.0.post0
1.10.1
1.2
1.3
1.3.post0
1.3.post1
1.4
1.4.1
1.4.1.post0
1.4.1.post1
1.5.0
1.5.0.post0
1.6.0
1.7.0
1.7.1
1.7.2
1.7.3
1.8.0
1.8.1
1.8.2
1.8.2.post0
1.8.2.post1
1.9.0
1.9.1
1.9.1.post0
1.9.2
1.9.2.post0
v1.4.1
v1.4.0
v1.3.0
v1.2.0
v1.1.1
v1.1.0
v1.0.2
v1.0.1
v1.0.0
v0.9.1.post1
v0.9.1.post0
v0.9.0.post5
v0.9.0.post4
v0.9.0.post3
v0.9.0
v0.8.2
v0.8.1
v0.8.0
v0.7.5.post0
v0.7.3
v0.7.2
v0.7.1
v0.7.0
v0.6.1
v0.6.0
v0.5.1
v0.4.8
v0.4.7
v0.4.6
v0.4.5
v0.4.4
v0.4.0
v0.3.0
v0.2.2
v.0.2.1-8
v.0.2.1-5
v.0.2.1-4
v.0.2.1-3
v.0.2.1-2
v.0.2.0
v.0.1.6
v.0.1.5
v.0.1.4
v.0.1.2
v.0.1.1
v.0.1.0
Fixed in
1.11.0
References
Updated Jun 10, 2026 · Source: OSV.dev
CVE-2023-47116
GHSA-p59w-9gqw-wj8r
PYSEC-2024-127
Jan 31, 2024
Label Studio SSRF on Import Bypassing `SSRF_PROTECTION_ENABLED` Protections
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
IntroductionThis write-up describes a vulnerability found in Label Studio, a popular open source data labeling tool. The vulnerability affects all versions of Label Studio prior to OverviewLabel Studio's SSRF protections that can be enabled by setting the DescriptionThe following
The
The issue here is the SSRF validation is only performed before the request is sent, and does not validate the destination IP address. Therefore, an attacker can either redirect the request or perform a DNS rebinding attack to bypass this protection. Proof of ConceptBoth the HTTP redirection and DNS rebinding methods for bypassing Label Studio's SSRF protections are explained below. HTTP RedirectionThe python
DNS Rebinding AttackDNS rebinding can bypass SSRF protections by resolving to an external IP address for the first resolution, but when the request is sent resolves to an internal IP address that is blocked. For an example, the domain ImpactSSRF vulnerabilities pose a significant risk on cloud environments, since instance credentials are managed by internal web APIs. An attacker can bypass Label Studio's SSRF protections to access internal web servers and partially compromise the confidentiality of those internal servers. Remediation Advice
Discovered
Affected versions
0.4.1
0.4.2
0.4.3
0.4.4
0.4.4.post1
0.4.4.post2
0.4.5
0.4.6
0.4.6.post1
0.4.6.post2
0.4.7
0.4.8
+ 67 more Show less
0.5.0
0.5.1
0.6.0
0.6.1
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.4.post0
0.7.4.post1
0.7.5.post1
0.7.5.post2
0.8.0
0.8.0.post0
0.8.1
0.8.1.post0
0.8.2
0.8.2.post0
0.9.0
0.9.0.post2
0.9.0.post3
0.9.0.post4
0.9.0.post5
0.9.1
0.9.1.post0
0.9.1.post1
0.9.1.post2
1.0.0
1.0.0.post0
1.0.0.post1
1.0.0.post2
1.0.0.post3
1.0.1
1.0.2
1.0.2.post0
1.1.0
1.1.0rc0
1.1.1
1.10.0
1.10.0.post0
1.10.1
1.2
1.3
1.3.post0
1.3.post1
1.4
1.4.1
1.4.1.post0
1.4.1.post1
1.5.0
1.5.0.post0
1.6.0
1.7.0
1.7.1
1.7.2
1.7.3
1.8.0
1.8.1
1.8.2
1.8.2.post0
1.8.2.post1
1.9.0
1.9.1
1.9.1.post0
1.9.2
1.9.2.post0
Fixed in
1.11.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-23633
GHSA-fq23-g58m-799r
PYSEC-2024-128
Jan 24, 2024
Cross-site Scripting Vulnerability on Data Import
4.7
/ 10
Medium
Network
Low
None
Required
Changed
Low
None
None
IntroductionThis write-up describes a vulnerability found in Label Studio, a popular open source data labeling tool. The vulnerability affects all versions of Label Studio prior to OverviewLabel Studio had a remote import feature allowed users to import data from a remote web source, that was downloaded and could be viewed on the website. This feature could had been abused to download a HTML file that executed malicious JavaScript code in the context of the Label Studio website. DescriptionThe following code snippet in Label Studio showed that is a URL passed the SSRF verification checks, the contents of the file would be downloaded using the filename in the URL.
The downloaded file path could then be retrieved by sending a request to
Since the Proof of ConceptBelow were the steps to recreate this issue:
ImpactExecuting arbitrary JavaScript could result in an attacker performing malicious actions on Label Studio users if they visit the crafted avatar image. For an example, an attacker can craft a JavaScript payload that adds a new Django Super Administrator user if a Django administrator visits the image. Remediation Advice
Discovered
Affected versions
0.4.1
0.4.2
0.4.3
0.4.4
0.4.4.post1
0.4.4.post2
0.4.5
0.4.6
0.4.6.post1
0.4.6.post2
0.4.7
0.4.8
+ 66 more Show less
0.5.0
0.5.1
0.6.0
0.6.1
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.4.post0
0.7.4.post1
0.7.5.post1
0.7.5.post2
0.8.0
0.8.0.post0
0.8.1
0.8.1.post0
0.8.2
0.8.2.post0
0.9.0
0.9.0.post2
0.9.0.post3
0.9.0.post4
0.9.0.post5
0.9.1
0.9.1.post0
0.9.1.post1
0.9.1.post2
1.0.0
1.0.0.post0
1.0.0.post1
1.0.0.post2
1.0.0.post3
1.0.1
1.0.2
1.0.2.post0
1.1.0
1.1.0rc0
1.1.1
1.10.0
1.10.0.post0
1.2
1.3
1.3.post0
1.3.post1
1.4
1.4.1
1.4.1.post0
1.4.1.post1
1.5.0
1.5.0.post0
1.6.0
1.7.0
1.7.1
1.7.2
1.7.3
1.8.0
1.8.1
1.8.2
1.8.2.post0
1.8.2.post1
1.9.0
1.9.1
1.9.1.post0
1.9.2
1.9.2.post0
Fixed in
1.10.1
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2023-47115
GHSA-q68h-xwq5-mm7x
PYSEC-2024-126
Jan 24, 2024
Cross-site Scripting Vulnerability on Avatar Upload
7.1
/ 10
High
Network
Low
None
Required
Changed
Low
Low
Low
IntroductionThis write-up describes a vulnerability found in Label Studio, a popular open source data labeling tool. The vulnerability affects all versions of Label Studio prior to OverviewLabel Studio has a cross-site scripting (XSS) vulnerability that could be exploited when an authenticated user uploads a crafted image file for their avatar that gets rendered as a HTML file on the website. DescriptionThe following code snippet in Label Studio shows that the only verification check is that the file is an image by extracting the dimensions from the file.
Label Studio serves avatar images using Django's built-in
The issue with the Django Proof of ConceptBelow are the steps to reproduce this issue and execute JavaScript code in the context of the Label Studio website.
ImpactExecuting arbitrary JavaScript could result in an attacker performing malicious actions on Label Studio users if they visit the crafted avatar image. For an example, an attacker can craft a JavaScript payload that adds a new Django Super Administrator user if a Django administrator visits the image. Remediation Advice
Discovered
Affected versions
0.4.1
0.4.2
0.4.3
0.4.4
0.4.4.post1
0.4.4.post2
0.4.5
0.4.6
0.4.6.post1
0.4.6.post2
0.4.7
0.4.8
+ 62 more Show less
0.5.0
0.5.1
0.6.0
0.6.1
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.4.post0
0.7.4.post1
0.7.5.post1
0.7.5.post2
0.8.0
0.8.0.post0
0.8.1
0.8.1.post0
0.8.2
0.8.2.post0
0.9.0
0.9.0.post2
0.9.0.post3
0.9.0.post4
0.9.0.post5
0.9.1
0.9.1.post0
0.9.1.post1
0.9.1.post2
1.0.0
1.0.0.post0
1.0.0.post1
1.0.0.post2
1.0.0.post3
1.0.1
1.0.2
1.0.2.post0
1.1.0
1.1.0rc0
1.1.1
1.2
1.3
1.3.post0
1.3.post1
1.4
1.4.1
1.4.1.post0
1.4.1.post1
1.5.0
1.5.0.post0
1.6.0
1.7.0
1.7.1
1.7.2
1.7.3
1.8.0
1.8.1
1.8.2
1.8.2.post0
1.8.2.post1
1.9.0
1.9.1
1.9.1.post0
Fixed in
1.9.2
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2023-47117
GHSA-6hjj-gq77-j4qw
PYSEC-2023-275
Nov 14, 2023
Label Studio Object Relational Mapper Leak Vulnerability in Filtering Task
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
IntroductionThis write-up describes a vulnerability found in Label Studio, a popular open source data labeling tool. The vulnerability affects all versions of Label Studio prior to OverviewIn all current versions of Label Studio, the application allows users to insecurely set filters for filtering tasks. An attacker can construct a filter chain to filter tasks based on sensitive fields for all user accounts on the platform by exploiting Django's Object Relational Mapper (ORM). Since the results of query can be manipulated by the ORM filter, an attacker can leak these sensitive fields character by character. For an example, the following filter chain will task results by the password hash of an account on Label Studio.
For consistency, this type of vulnerability will be termed as ORM Leak in the rest of this disclosure. In addition, Label Studio had a hard coded secret key that an attacker can use to forge a session token of any user by exploiting this ORM Leak vulnerability to leak account password hashes. DescriptionThe following code snippet from the
These
The
The following code snippet of the
Finally, the
Proof of ConceptBelow are the steps to exploit about how to exploit this vulnerability to leak the password hash of an account on Label Studio.
The following example GIF demonstrates exploiting this ORM Leak vulnerability to retrieve the password hash
ImpactThis vulnerability can be exploited to completely compromise the confidentiality of highly sensitive account information, such as account password hashes. For all versions Remediation Advice
Discovered
| ||
1.3.post0
pre
12 CVEs
CVE-2026-22033
PYSEC-2026-1502
GHSA-2mq9-hm29-8qch
Jul 07, 2026
Label Studio is vulnerable to full account takeover by chaining Stored XSS + IDOR in User Profile via custom_hotkeys field
Critical
Network
Low
Low
None
PrologueThese vulnerabilities have been found and chained by DCODX-AI. Validation of the exploit chain has been confirmed manually. SummaryA persistent stored cross-site scripting (XSS) vulnerability exists in the custom_hotkeys functionality of the application. An authenticated attacker (or one who can trick a user/administrator into updating their custom_hotkeys) can inject JavaScript code that executes in other users’ browsers when those users load any page using the DetailsWithin
Here, user.custom_hotkeys is run through json_dumps_ensure_ascii (in In
The serializer allows
When another user loads a page using templates/base.html (for example PoC
Example request
Example response
ImpactExploitation impact:
Who is impacted:
Affected versions
0.4.1
0.4.2
0.4.3
0.4.4
0.4.4.post1
0.4.4.post2
0.4.5
0.4.6
0.4.6.post1
0.4.6.post2
0.4.7
0.4.8
+ 83 more Show less
0.5.0
0.5.1
0.6.0
0.6.1
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.4.post0
0.7.4.post1
0.7.5.post1
0.7.5.post2
0.8.0
0.8.0.post0
0.8.1
0.8.1.post0
0.8.2
0.8.2.post0
0.9.0
0.9.0.post2
0.9.0.post3
0.9.0.post4
0.9.0.post5
0.9.1
0.9.1.post0
0.9.1.post1
0.9.1.post2
1.0.0
1.0.0.post0
1.0.0.post1
1.0.0.post2
1.0.0.post3
1.0.1
1.0.2
1.0.2.post0
1.1.0
1.1.0rc0
1.1.1
1.10.0
1.10.0.post0
1.10.1
1.11.0
1.12.0
1.12.0.post0
1.12.1
1.13.0
1.13.1
1.14.0
1.14.0.post0
1.15.0
1.16.0
1.17.0
1.18.0
1.19.0
1.2
1.20.0
1.21.0
1.22.0
1.3
1.3.post0
1.3.post1
1.4
1.4.1
1.4.1.post0
1.4.1.post1
1.5.0
1.5.0.post0
1.6.0
1.7.0
1.7.1
1.7.2
1.7.3
1.8.0
1.8.1
1.8.2
1.8.2.post0
1.8.2.post1
1.9.0
1.9.1
1.9.1.post0
1.9.2
1.9.2.post0
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-25297
PYSEC-2026-1503
GHSA-m238-fmcw-wh58
Jul 07, 2026
Label Studio allows Server-Side Request Forgery in the S3 Storage Endpoint
8.6
/ 10
High
Network
Low
None
None
Changed
High
None
None
DescriptionLabel Studio's S3 storage integration feature contains a Server-Side Request Forgery (SSRF) vulnerability in its endpoint configuration. When creating an S3 storage connection, the application allows users to specify a custom S3 endpoint URL via the s3_endpoint parameter. This endpoint URL is passed directly to the boto3 AWS SDK without proper validation or restrictions on the protocol or destination. The vulnerability allows an attacker to make the application send HTTP requests to arbitrary internal services by specifying them as the S3 endpoint. When the storage sync operation is triggered, the application attempts to make S3 API calls to the specified endpoint, effectively making HTTP requests to the target service and returning the response in error messages. This SSRF vulnerability enables attackers to bypass network segmentation and access internal services that should not be accessible from the external network. The vulnerability is particularly severe because error messages from failed requests contain the full response body, allowing data exfiltration from internal services. Steps to reproduce
The application will attempt to connect to the specified endpoint URL as if it were an S3 service. When the request fails due to invalid S3 API responses, the error message will contain the raw response from the internal service, allowing access to internal resources. Mitigations
ImpactThis vulnerability has high severity as it allows authenticated users to make requests to arbitrary internal services from the application server, potentially exposing sensitive internal resources and bypassing network segmentation. The inclusion of response data in error messages makes this particularly effective for data exfiltration. Affected versions
0.4.1
0.4.2
0.4.3
0.4.4
0.4.4.post1
0.4.4.post2
0.4.5
0.4.6
0.4.6.post1
0.4.6.post2
0.4.7
0.4.8
+ 76 more Show less
0.5.0
0.5.1
0.6.0
0.6.1
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.4.post0
0.7.4.post1
0.7.5.post1
0.7.5.post2
0.8.0
0.8.0.post0
0.8.1
0.8.1.post0
0.8.2
0.8.2.post0
0.9.0
0.9.0.post2
0.9.0.post3
0.9.0.post4
0.9.0.post5
0.9.1
0.9.1.post0
0.9.1.post1
0.9.1.post2
1.0.0
1.0.0.post0
1.0.0.post1
1.0.0.post2
1.0.0.post3
1.0.1
1.0.2
1.0.2.post0
1.1.0
1.1.0rc0
1.1.1
1.10.0
1.10.0.post0
1.10.1
1.11.0
1.12.0
1.12.0.post0
1.12.1
1.13.0
1.13.1
1.14.0
1.14.0.post0
1.15.0
1.2
1.3
1.3.post0
1.3.post1
1.4
1.4.1
1.4.1.post0
1.4.1.post1
1.5.0
1.5.0.post0
1.6.0
1.7.0
1.7.1
1.7.2
1.7.3
1.8.0
1.8.1
1.8.2
1.8.2.post0
1.8.2.post1
1.9.0
1.9.1
1.9.1.post0
1.9.2
1.9.2.post0
Fixed in
1.16.0
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-25296
PYSEC-2026-1504
GHSA-wpq5-3366-mqw4
Jul 07, 2026
Label Studio allows Cross-Site Scripting (XSS) via GET request to `/projects/upload-example` endpoint
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
DescriptionLabel Studio's The vulnerability exists because the upload-example endpoint renders user-provided HTML content without proper sanitization on a GET request. This allows attackers to inject and execute arbitrary JavaScript in victims' browsers by getting them to visit a maliciously crafted URL. This is considered vulnerable because it enables attackers to execute JavaScript in victims' contexts, potentially allowing theft of sensitive data, session hijacking, or other malicious actions. Steps to reproduce
When executed, the payload causes the application to render an HTML page containing an img tag that fails to load, triggering the onerror event handler which executes base64-decoded JavaScript, demonstrating successful XSS execution in the victim's browser. Mitigations
ImpactThe vulnerability requires no special privileges and can be exploited by getting a victim to visit a crafted URL. The impact is high as it allows arbitrary JavaScript execution in victims' browsers, potentially exposing sensitive data or enabling account takeover through session theft. Affected versions
0.4.1
0.4.2
0.4.3
0.4.4
0.4.4.post1
0.4.4.post2
0.4.5
0.4.6
0.4.6.post1
0.4.6.post2
0.4.7
0.4.8
+ 76 more Show less
0.5.0
0.5.1
0.6.0
0.6.1
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.4.post0
0.7.4.post1
0.7.5.post1
0.7.5.post2
0.8.0
0.8.0.post0
0.8.1
0.8.1.post0
0.8.2
0.8.2.post0
0.9.0
0.9.0.post2
0.9.0.post3
0.9.0.post4
0.9.0.post5
0.9.1
0.9.1.post0
0.9.1.post1
0.9.1.post2
1.0.0
1.0.0.post0
1.0.0.post1
1.0.0.post2
1.0.0.post3
1.0.1
1.0.2
1.0.2.post0
1.1.0
1.1.0rc0
1.1.1
1.10.0
1.10.0.post0
1.10.1
1.11.0
1.12.0
1.12.0.post0
1.12.1
1.13.0
1.13.1
1.14.0
1.14.0.post0
1.15.0
1.2
1.3
1.3.post0
1.3.post1
1.4
1.4.1
1.4.1.post0
1.4.1.post1
1.5.0
1.5.0.post0
1.6.0
1.7.0
1.7.1
1.7.2
1.7.3
1.8.0
1.8.1
1.8.2
1.8.2.post0
1.8.2.post1
1.9.0
1.9.1
1.9.1.post0
1.9.2
1.9.2.post0
Fixed in
1.16.0
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-47783
GHSA-8jhr-wpcm-hh4h
PYSEC-2025-124
May 15, 2025
label-studio vulnerable to Cross-Site Scripting (Reflected) via the label_config parameter.
High
Network
Low
None
SummaryThe vulnerability allows an attacker to inject a malicious script into the context of a web page, which can lead to data theft, unauthorized actions on behalf of the user, and other attacks. DetailsThe vulnerability is reproducible when sending a properly formatted request to the
The vulnerability is specifically located in line 57, where HttpResponse is used.
PoCSend the following request after changing the
Or you can create a vulnerable HTML page by changing
Impact
Affected versions
0.4.1
0.4.2
0.4.3
0.4.4
0.4.4.post1
0.4.4.post2
0.4.5
0.4.6
0.4.6.post1
0.4.6.post2
0.4.7
0.4.8
+ 78 more Show less
0.5.0
0.5.1
0.6.0
0.6.1
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.4.post0
0.7.4.post1
0.7.5.post1
0.7.5.post2
0.8.0
0.8.0.post0
0.8.1
0.8.1.post0
0.8.2
0.8.2.post0
0.9.0
0.9.0.post2
0.9.0.post3
0.9.0.post4
0.9.0.post5
0.9.1
0.9.1.post0
0.9.1.post1
0.9.1.post2
1.0.0
1.0.0.post0
1.0.0.post1
1.0.0.post2
1.0.0.post3
1.0.1
1.0.2
1.0.2.post0
1.1.0
1.1.0rc0
1.1.1
1.10.0
1.10.0.post0
1.10.1
1.11.0
1.12.0
1.12.0.post0
1.12.1
1.13.0
1.13.1
1.14.0
1.14.0.post0
1.15.0
1.16.0
1.17.0
1.2
1.3
1.3.post0
1.3.post1
1.4
1.4.1
1.4.1.post0
1.4.1.post1
1.5.0
1.5.0.post0
1.6.0
1.7.0
1.7.1
1.7.2
1.7.3
1.8.0
1.8.1
1.8.2
1.8.2.post0
1.8.2.post1
1.9.0
1.9.1
1.9.1.post0
1.9.2
1.9.2.post0
Fixed in
1.18.0
References
Updated Jun 06, 2026 · Source: OSV.dev
CVE-2024-26152
PYSEC-2024-249
GHSA-6xv9-957j-qfhg
Feb 22, 2024
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
SummaryOn all Label Studio versions prior to 1.11.0, data imported via file upload feature is not properly sanitized prior to being rendered within a DetailsNeed permission to use the "data import" function. This was reproduced on Label Studio 1.10.1. PoC
The following are the contents of the files used in the PoC
ImpactMalicious scripts can be injected into the code, and when linked with vulnerabilities such as CSRF, it can cause even greater damage. In particular, It can become a source of further attacks, especially when linked to social engineering. Affected versions
0.4.1
0.4.2
0.4.3
0.4.4
0.4.4.post1
0.4.4.post2
0.4.5
0.4.6
0.4.6.post1
0.4.6.post2
0.4.7
0.4.8
+ 113 more Show less
0.5.0
0.5.1
0.6.0
0.6.1
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.4.post0
0.7.4.post1
0.7.5.post1
0.7.5.post2
0.8.0
0.8.0.post0
0.8.1
0.8.1.post0
0.8.2
0.8.2.post0
0.9.0
0.9.0.post2
0.9.0.post3
0.9.0.post4
0.9.0.post5
0.9.1
0.9.1.post0
0.9.1.post1
0.9.1.post2
1.0.0
1.0.0.post0
1.0.0.post1
1.0.0.post2
1.0.0.post3
1.0.1
1.0.2
1.0.2.post0
1.1.0
1.1.0rc0
1.1.1
1.10.0
1.10.0.post0
1.10.1
1.2
1.3
1.3.post0
1.3.post1
1.4
1.4.1
1.4.1.post0
1.4.1.post1
1.5.0
1.5.0.post0
1.6.0
1.7.0
1.7.1
1.7.2
1.7.3
1.8.0
1.8.1
1.8.2
1.8.2.post0
1.8.2.post1
1.9.0
1.9.1
1.9.1.post0
1.9.2
1.9.2.post0
v1.4.1
v1.4.0
v1.3.0
v1.2.0
v1.1.1
v1.1.0
v1.0.2
v1.0.1
v1.0.0
v0.9.1.post1
v0.9.1.post0
v0.9.0.post5
v0.9.0.post4
v0.9.0.post3
v0.9.0
v0.8.2
v0.8.1
v0.8.0
v0.7.5.post0
v0.7.3
v0.7.2
v0.7.1
v0.7.0
v0.6.1
v0.6.0
v0.5.1
v0.4.8
v0.4.7
v0.4.6
v0.4.5
v0.4.4
v0.4.0
v0.3.0
v0.2.2
v.0.2.1-8
v.0.2.1-5
v.0.2.1-4
v.0.2.1-3
v.0.2.1-2
v.0.2.0
v.0.1.6
v.0.1.5
v.0.1.4
v.0.1.2
v.0.1.1
v.0.1.0
Fixed in
1.11.0
References
Updated Jun 10, 2026 · Source: OSV.dev
CVE-2023-47116
GHSA-p59w-9gqw-wj8r
PYSEC-2024-127
Jan 31, 2024
Label Studio SSRF on Import Bypassing `SSRF_PROTECTION_ENABLED` Protections
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
IntroductionThis write-up describes a vulnerability found in Label Studio, a popular open source data labeling tool. The vulnerability affects all versions of Label Studio prior to OverviewLabel Studio's SSRF protections that can be enabled by setting the DescriptionThe following
The
The issue here is the SSRF validation is only performed before the request is sent, and does not validate the destination IP address. Therefore, an attacker can either redirect the request or perform a DNS rebinding attack to bypass this protection. Proof of ConceptBoth the HTTP redirection and DNS rebinding methods for bypassing Label Studio's SSRF protections are explained below. HTTP RedirectionThe python
DNS Rebinding AttackDNS rebinding can bypass SSRF protections by resolving to an external IP address for the first resolution, but when the request is sent resolves to an internal IP address that is blocked. For an example, the domain ImpactSSRF vulnerabilities pose a significant risk on cloud environments, since instance credentials are managed by internal web APIs. An attacker can bypass Label Studio's SSRF protections to access internal web servers and partially compromise the confidentiality of those internal servers. Remediation Advice
Discovered
Affected versions
0.4.1
0.4.2
0.4.3
0.4.4
0.4.4.post1
0.4.4.post2
0.4.5
0.4.6
0.4.6.post1
0.4.6.post2
0.4.7
0.4.8
+ 67 more Show less
0.5.0
0.5.1
0.6.0
0.6.1
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.4.post0
0.7.4.post1
0.7.5.post1
0.7.5.post2
0.8.0
0.8.0.post0
0.8.1
0.8.1.post0
0.8.2
0.8.2.post0
0.9.0
0.9.0.post2
0.9.0.post3
0.9.0.post4
0.9.0.post5
0.9.1
0.9.1.post0
0.9.1.post1
0.9.1.post2
1.0.0
1.0.0.post0
1.0.0.post1
1.0.0.post2
1.0.0.post3
1.0.1
1.0.2
1.0.2.post0
1.1.0
1.1.0rc0
1.1.1
1.10.0
1.10.0.post0
1.10.1
1.2
1.3
1.3.post0
1.3.post1
1.4
1.4.1
1.4.1.post0
1.4.1.post1
1.5.0
1.5.0.post0
1.6.0
1.7.0
1.7.1
1.7.2
1.7.3
1.8.0
1.8.1
1.8.2
1.8.2.post0
1.8.2.post1
1.9.0
1.9.1
1.9.1.post0
1.9.2
1.9.2.post0
Fixed in
1.11.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-23633
GHSA-fq23-g58m-799r
PYSEC-2024-128
Jan 24, 2024
Cross-site Scripting Vulnerability on Data Import
4.7
/ 10
Medium
Network
Low
None
Required
Changed
Low
None
None
IntroductionThis write-up describes a vulnerability found in Label Studio, a popular open source data labeling tool. The vulnerability affects all versions of Label Studio prior to OverviewLabel Studio had a remote import feature allowed users to import data from a remote web source, that was downloaded and could be viewed on the website. This feature could had been abused to download a HTML file that executed malicious JavaScript code in the context of the Label Studio website. DescriptionThe following code snippet in Label Studio showed that is a URL passed the SSRF verification checks, the contents of the file would be downloaded using the filename in the URL.
The downloaded file path could then be retrieved by sending a request to
Since the Proof of ConceptBelow were the steps to recreate this issue:
ImpactExecuting arbitrary JavaScript could result in an attacker performing malicious actions on Label Studio users if they visit the crafted avatar image. For an example, an attacker can craft a JavaScript payload that adds a new Django Super Administrator user if a Django administrator visits the image. Remediation Advice
Discovered
Affected versions
0.4.1
0.4.2
0.4.3
0.4.4
0.4.4.post1
0.4.4.post2
0.4.5
0.4.6
0.4.6.post1
0.4.6.post2
0.4.7
0.4.8
+ 66 more Show less
0.5.0
0.5.1
0.6.0
0.6.1
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.4.post0
0.7.4.post1
0.7.5.post1
0.7.5.post2
0.8.0
0.8.0.post0
0.8.1
0.8.1.post0
0.8.2
0.8.2.post0
0.9.0
0.9.0.post2
0.9.0.post3
0.9.0.post4
0.9.0.post5
0.9.1
0.9.1.post0
0.9.1.post1
0.9.1.post2
1.0.0
1.0.0.post0
1.0.0.post1
1.0.0.post2
1.0.0.post3
1.0.1
1.0.2
1.0.2.post0
1.1.0
1.1.0rc0
1.1.1
1.10.0
1.10.0.post0
1.2
1.3
1.3.post0
1.3.post1
1.4
1.4.1
1.4.1.post0
1.4.1.post1
1.5.0
1.5.0.post0
1.6.0
1.7.0
1.7.1
1.7.2
1.7.3
1.8.0
1.8.1
1.8.2
1.8.2.post0
1.8.2.post1
1.9.0
1.9.1
1.9.1.post0
1.9.2
1.9.2.post0
Fixed in
1.10.1
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2023-47115
GHSA-q68h-xwq5-mm7x
PYSEC-2024-126
Jan 24, 2024
Cross-site Scripting Vulnerability on Avatar Upload
7.1
/ 10
High
Network
Low
None
Required
Changed
Low
Low
Low
IntroductionThis write-up describes a vulnerability found in Label Studio, a popular open source data labeling tool. The vulnerability affects all versions of Label Studio prior to OverviewLabel Studio has a cross-site scripting (XSS) vulnerability that could be exploited when an authenticated user uploads a crafted image file for their avatar that gets rendered as a HTML file on the website. DescriptionThe following code snippet in Label Studio shows that the only verification check is that the file is an image by extracting the dimensions from the file.
Label Studio serves avatar images using Django's built-in
The issue with the Django Proof of ConceptBelow are the steps to reproduce this issue and execute JavaScript code in the context of the Label Studio website.
ImpactExecuting arbitrary JavaScript could result in an attacker performing malicious actions on Label Studio users if they visit the crafted avatar image. For an example, an attacker can craft a JavaScript payload that adds a new Django Super Administrator user if a Django administrator visits the image. Remediation Advice
Discovered
Affected versions
0.4.1
0.4.2
0.4.3
0.4.4
0.4.4.post1
0.4.4.post2
0.4.5
0.4.6
0.4.6.post1
0.4.6.post2
0.4.7
0.4.8
+ 62 more Show less
0.5.0
0.5.1
0.6.0
0.6.1
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.4.post0
0.7.4.post1
0.7.5.post1
0.7.5.post2
0.8.0
0.8.0.post0
0.8.1
0.8.1.post0
0.8.2
0.8.2.post0
0.9.0
0.9.0.post2
0.9.0.post3
0.9.0.post4
0.9.0.post5
0.9.1
0.9.1.post0
0.9.1.post1
0.9.1.post2
1.0.0
1.0.0.post0
1.0.0.post1
1.0.0.post2
1.0.0.post3
1.0.1
1.0.2
1.0.2.post0
1.1.0
1.1.0rc0
1.1.1
1.2
1.3
1.3.post0
1.3.post1
1.4
1.4.1
1.4.1.post0
1.4.1.post1
1.5.0
1.5.0.post0
1.6.0
1.7.0
1.7.1
1.7.2
1.7.3
1.8.0
1.8.1
1.8.2
1.8.2.post0
1.8.2.post1
1.9.0
1.9.1
1.9.1.post0
Fixed in
1.9.2
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2023-47117
GHSA-6hjj-gq77-j4qw
PYSEC-2023-275
Nov 14, 2023
Label Studio Object Relational Mapper Leak Vulnerability in Filtering Task
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
IntroductionThis write-up describes a vulnerability found in Label Studio, a popular open source data labeling tool. The vulnerability affects all versions of Label Studio prior to OverviewIn all current versions of Label Studio, the application allows users to insecurely set filters for filtering tasks. An attacker can construct a filter chain to filter tasks based on sensitive fields for all user accounts on the platform by exploiting Django's Object Relational Mapper (ORM). Since the results of query can be manipulated by the ORM filter, an attacker can leak these sensitive fields character by character. For an example, the following filter chain will task results by the password hash of an account on Label Studio.
For consistency, this type of vulnerability will be termed as ORM Leak in the rest of this disclosure. In addition, Label Studio had a hard coded secret key that an attacker can use to forge a session token of any user by exploiting this ORM Leak vulnerability to leak account password hashes. DescriptionThe following code snippet from the
These
The
The following code snippet of the
Finally, the
Proof of ConceptBelow are the steps to exploit about how to exploit this vulnerability to leak the password hash of an account on Label Studio.
The following example GIF demonstrates exploiting this ORM Leak vulnerability to retrieve the password hash
ImpactThis vulnerability can be exploited to completely compromise the confidentiality of highly sensitive account information, such as account password hashes. For all versions Remediation Advice
Discovered
| ||
1.3
minor
12 CVEs
CVE-2026-22033
PYSEC-2026-1502
GHSA-2mq9-hm29-8qch
Jul 07, 2026
Label Studio is vulnerable to full account takeover by chaining Stored XSS + IDOR in User Profile via custom_hotkeys field
Critical
Network
Low
Low
None
PrologueThese vulnerabilities have been found and chained by DCODX-AI. Validation of the exploit chain has been confirmed manually. SummaryA persistent stored cross-site scripting (XSS) vulnerability exists in the custom_hotkeys functionality of the application. An authenticated attacker (or one who can trick a user/administrator into updating their custom_hotkeys) can inject JavaScript code that executes in other users’ browsers when those users load any page using the DetailsWithin
Here, user.custom_hotkeys is run through json_dumps_ensure_ascii (in In
The serializer allows
When another user loads a page using templates/base.html (for example PoC
Example request
Example response
ImpactExploitation impact:
Who is impacted:
Affected versions
0.4.1
0.4.2
0.4.3
0.4.4
0.4.4.post1
0.4.4.post2
0.4.5
0.4.6
0.4.6.post1
0.4.6.post2
0.4.7
0.4.8
+ 83 more Show less
0.5.0
0.5.1
0.6.0
0.6.1
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.4.post0
0.7.4.post1
0.7.5.post1
0.7.5.post2
0.8.0
0.8.0.post0
0.8.1
0.8.1.post0
0.8.2
0.8.2.post0
0.9.0
0.9.0.post2
0.9.0.post3
0.9.0.post4
0.9.0.post5
0.9.1
0.9.1.post0
0.9.1.post1
0.9.1.post2
1.0.0
1.0.0.post0
1.0.0.post1
1.0.0.post2
1.0.0.post3
1.0.1
1.0.2
1.0.2.post0
1.1.0
1.1.0rc0
1.1.1
1.10.0
1.10.0.post0
1.10.1
1.11.0
1.12.0
1.12.0.post0
1.12.1
1.13.0
1.13.1
1.14.0
1.14.0.post0
1.15.0
1.16.0
1.17.0
1.18.0
1.19.0
1.2
1.20.0
1.21.0
1.22.0
1.3
1.3.post0
1.3.post1
1.4
1.4.1
1.4.1.post0
1.4.1.post1
1.5.0
1.5.0.post0
1.6.0
1.7.0
1.7.1
1.7.2
1.7.3
1.8.0
1.8.1
1.8.2
1.8.2.post0
1.8.2.post1
1.9.0
1.9.1
1.9.1.post0
1.9.2
1.9.2.post0
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-25297
PYSEC-2026-1503
GHSA-m238-fmcw-wh58
Jul 07, 2026
Label Studio allows Server-Side Request Forgery in the S3 Storage Endpoint
8.6
/ 10
High
Network
Low
None
None
Changed
High
None
None
DescriptionLabel Studio's S3 storage integration feature contains a Server-Side Request Forgery (SSRF) vulnerability in its endpoint configuration. When creating an S3 storage connection, the application allows users to specify a custom S3 endpoint URL via the s3_endpoint parameter. This endpoint URL is passed directly to the boto3 AWS SDK without proper validation or restrictions on the protocol or destination. The vulnerability allows an attacker to make the application send HTTP requests to arbitrary internal services by specifying them as the S3 endpoint. When the storage sync operation is triggered, the application attempts to make S3 API calls to the specified endpoint, effectively making HTTP requests to the target service and returning the response in error messages. This SSRF vulnerability enables attackers to bypass network segmentation and access internal services that should not be accessible from the external network. The vulnerability is particularly severe because error messages from failed requests contain the full response body, allowing data exfiltration from internal services. Steps to reproduce
The application will attempt to connect to the specified endpoint URL as if it were an S3 service. When the request fails due to invalid S3 API responses, the error message will contain the raw response from the internal service, allowing access to internal resources. Mitigations
ImpactThis vulnerability has high severity as it allows authenticated users to make requests to arbitrary internal services from the application server, potentially exposing sensitive internal resources and bypassing network segmentation. The inclusion of response data in error messages makes this particularly effective for data exfiltration. Affected versions
0.4.1
0.4.2
0.4.3
0.4.4
0.4.4.post1
0.4.4.post2
0.4.5
0.4.6
0.4.6.post1
0.4.6.post2
0.4.7
0.4.8
+ 76 more Show less
0.5.0
0.5.1
0.6.0
0.6.1
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.4.post0
0.7.4.post1
0.7.5.post1
0.7.5.post2
0.8.0
0.8.0.post0
0.8.1
0.8.1.post0
0.8.2
0.8.2.post0
0.9.0
0.9.0.post2
0.9.0.post3
0.9.0.post4
0.9.0.post5
0.9.1
0.9.1.post0
0.9.1.post1
0.9.1.post2
1.0.0
1.0.0.post0
1.0.0.post1
1.0.0.post2
1.0.0.post3
1.0.1
1.0.2
1.0.2.post0
1.1.0
1.1.0rc0
1.1.1
1.10.0
1.10.0.post0
1.10.1
1.11.0
1.12.0
1.12.0.post0
1.12.1
1.13.0
1.13.1
1.14.0
1.14.0.post0
1.15.0
1.2
1.3
1.3.post0
1.3.post1
1.4
1.4.1
1.4.1.post0
1.4.1.post1
1.5.0
1.5.0.post0
1.6.0
1.7.0
1.7.1
1.7.2
1.7.3
1.8.0
1.8.1
1.8.2
1.8.2.post0
1.8.2.post1
1.9.0
1.9.1
1.9.1.post0
1.9.2
1.9.2.post0
Fixed in
1.16.0
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-25296
PYSEC-2026-1504
GHSA-wpq5-3366-mqw4
Jul 07, 2026
Label Studio allows Cross-Site Scripting (XSS) via GET request to `/projects/upload-example` endpoint
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
DescriptionLabel Studio's The vulnerability exists because the upload-example endpoint renders user-provided HTML content without proper sanitization on a GET request. This allows attackers to inject and execute arbitrary JavaScript in victims' browsers by getting them to visit a maliciously crafted URL. This is considered vulnerable because it enables attackers to execute JavaScript in victims' contexts, potentially allowing theft of sensitive data, session hijacking, or other malicious actions. Steps to reproduce
When executed, the payload causes the application to render an HTML page containing an img tag that fails to load, triggering the onerror event handler which executes base64-decoded JavaScript, demonstrating successful XSS execution in the victim's browser. Mitigations
ImpactThe vulnerability requires no special privileges and can be exploited by getting a victim to visit a crafted URL. The impact is high as it allows arbitrary JavaScript execution in victims' browsers, potentially exposing sensitive data or enabling account takeover through session theft. Affected versions
0.4.1
0.4.2
0.4.3
0.4.4
0.4.4.post1
0.4.4.post2
0.4.5
0.4.6
0.4.6.post1
0.4.6.post2
0.4.7
0.4.8
+ 76 more Show less
0.5.0
0.5.1
0.6.0
0.6.1
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.4.post0
0.7.4.post1
0.7.5.post1
0.7.5.post2
0.8.0
0.8.0.post0
0.8.1
0.8.1.post0
0.8.2
0.8.2.post0
0.9.0
0.9.0.post2
0.9.0.post3
0.9.0.post4
0.9.0.post5
0.9.1
0.9.1.post0
0.9.1.post1
0.9.1.post2
1.0.0
1.0.0.post0
1.0.0.post1
1.0.0.post2
1.0.0.post3
1.0.1
1.0.2
1.0.2.post0
1.1.0
1.1.0rc0
1.1.1
1.10.0
1.10.0.post0
1.10.1
1.11.0
1.12.0
1.12.0.post0
1.12.1
1.13.0
1.13.1
1.14.0
1.14.0.post0
1.15.0
1.2
1.3
1.3.post0
1.3.post1
1.4
1.4.1
1.4.1.post0
1.4.1.post1
1.5.0
1.5.0.post0
1.6.0
1.7.0
1.7.1
1.7.2
1.7.3
1.8.0
1.8.1
1.8.2
1.8.2.post0
1.8.2.post1
1.9.0
1.9.1
1.9.1.post0
1.9.2
1.9.2.post0
Fixed in
1.16.0
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-47783
GHSA-8jhr-wpcm-hh4h
PYSEC-2025-124
May 15, 2025
label-studio vulnerable to Cross-Site Scripting (Reflected) via the label_config parameter.
High
Network
Low
None
SummaryThe vulnerability allows an attacker to inject a malicious script into the context of a web page, which can lead to data theft, unauthorized actions on behalf of the user, and other attacks. DetailsThe vulnerability is reproducible when sending a properly formatted request to the
The vulnerability is specifically located in line 57, where HttpResponse is used.
PoCSend the following request after changing the
Or you can create a vulnerable HTML page by changing
Impact
Affected versions
0.4.1
0.4.2
0.4.3
0.4.4
0.4.4.post1
0.4.4.post2
0.4.5
0.4.6
0.4.6.post1
0.4.6.post2
0.4.7
0.4.8
+ 78 more Show less
0.5.0
0.5.1
0.6.0
0.6.1
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.4.post0
0.7.4.post1
0.7.5.post1
0.7.5.post2
0.8.0
0.8.0.post0
0.8.1
0.8.1.post0
0.8.2
0.8.2.post0
0.9.0
0.9.0.post2
0.9.0.post3
0.9.0.post4
0.9.0.post5
0.9.1
0.9.1.post0
0.9.1.post1
0.9.1.post2
1.0.0
1.0.0.post0
1.0.0.post1
1.0.0.post2
1.0.0.post3
1.0.1
1.0.2
1.0.2.post0
1.1.0
1.1.0rc0
1.1.1
1.10.0
1.10.0.post0
1.10.1
1.11.0
1.12.0
1.12.0.post0
1.12.1
1.13.0
1.13.1
1.14.0
1.14.0.post0
1.15.0
1.16.0
1.17.0
1.2
1.3
1.3.post0
1.3.post1
1.4
1.4.1
1.4.1.post0
1.4.1.post1
1.5.0
1.5.0.post0
1.6.0
1.7.0
1.7.1
1.7.2
1.7.3
1.8.0
1.8.1
1.8.2
1.8.2.post0
1.8.2.post1
1.9.0
1.9.1
1.9.1.post0
1.9.2
1.9.2.post0
Fixed in
1.18.0
References
Updated Jun 06, 2026 · Source: OSV.dev
CVE-2024-26152
PYSEC-2024-249
GHSA-6xv9-957j-qfhg
Feb 22, 2024
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
SummaryOn all Label Studio versions prior to 1.11.0, data imported via file upload feature is not properly sanitized prior to being rendered within a DetailsNeed permission to use the "data import" function. This was reproduced on Label Studio 1.10.1. PoC
The following are the contents of the files used in the PoC
ImpactMalicious scripts can be injected into the code, and when linked with vulnerabilities such as CSRF, it can cause even greater damage. In particular, It can become a source of further attacks, especially when linked to social engineering. Affected versions
0.4.1
0.4.2
0.4.3
0.4.4
0.4.4.post1
0.4.4.post2
0.4.5
0.4.6
0.4.6.post1
0.4.6.post2
0.4.7
0.4.8
+ 113 more Show less
0.5.0
0.5.1
0.6.0
0.6.1
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.4.post0
0.7.4.post1
0.7.5.post1
0.7.5.post2
0.8.0
0.8.0.post0
0.8.1
0.8.1.post0
0.8.2
0.8.2.post0
0.9.0
0.9.0.post2
0.9.0.post3
0.9.0.post4
0.9.0.post5
0.9.1
0.9.1.post0
0.9.1.post1
0.9.1.post2
1.0.0
1.0.0.post0
1.0.0.post1
1.0.0.post2
1.0.0.post3
1.0.1
1.0.2
1.0.2.post0
1.1.0
1.1.0rc0
1.1.1
1.10.0
1.10.0.post0
1.10.1
1.2
1.3
1.3.post0
1.3.post1
1.4
1.4.1
1.4.1.post0
1.4.1.post1
1.5.0
1.5.0.post0
1.6.0
1.7.0
1.7.1
1.7.2
1.7.3
1.8.0
1.8.1
1.8.2
1.8.2.post0
1.8.2.post1
1.9.0
1.9.1
1.9.1.post0
1.9.2
1.9.2.post0
v1.4.1
v1.4.0
v1.3.0
v1.2.0
v1.1.1
v1.1.0
v1.0.2
v1.0.1
v1.0.0
v0.9.1.post1
v0.9.1.post0
v0.9.0.post5
v0.9.0.post4
v0.9.0.post3
v0.9.0
v0.8.2
v0.8.1
v0.8.0
v0.7.5.post0
v0.7.3
v0.7.2
v0.7.1
v0.7.0
v0.6.1
v0.6.0
v0.5.1
v0.4.8
v0.4.7
v0.4.6
v0.4.5
v0.4.4
v0.4.0
v0.3.0
v0.2.2
v.0.2.1-8
v.0.2.1-5
v.0.2.1-4
v.0.2.1-3
v.0.2.1-2
v.0.2.0
v.0.1.6
v.0.1.5
v.0.1.4
v.0.1.2
v.0.1.1
v.0.1.0
Fixed in
1.11.0
References
Updated Jun 10, 2026 · Source: OSV.dev
CVE-2023-47116
GHSA-p59w-9gqw-wj8r
PYSEC-2024-127
Jan 31, 2024
Label Studio SSRF on Import Bypassing `SSRF_PROTECTION_ENABLED` Protections
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
IntroductionThis write-up describes a vulnerability found in Label Studio, a popular open source data labeling tool. The vulnerability affects all versions of Label Studio prior to OverviewLabel Studio's SSRF protections that can be enabled by setting the DescriptionThe following
The
The issue here is the SSRF validation is only performed before the request is sent, and does not validate the destination IP address. Therefore, an attacker can either redirect the request or perform a DNS rebinding attack to bypass this protection. Proof of ConceptBoth the HTTP redirection and DNS rebinding methods for bypassing Label Studio's SSRF protections are explained below. HTTP RedirectionThe python
DNS Rebinding AttackDNS rebinding can bypass SSRF protections by resolving to an external IP address for the first resolution, but when the request is sent resolves to an internal IP address that is blocked. For an example, the domain ImpactSSRF vulnerabilities pose a significant risk on cloud environments, since instance credentials are managed by internal web APIs. An attacker can bypass Label Studio's SSRF protections to access internal web servers and partially compromise the confidentiality of those internal servers. Remediation Advice
Discovered
Affected versions
0.4.1
0.4.2
0.4.3
0.4.4
0.4.4.post1
0.4.4.post2
0.4.5
0.4.6
0.4.6.post1
0.4.6.post2
0.4.7
0.4.8
+ 67 more Show less
0.5.0
0.5.1
0.6.0
0.6.1
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.4.post0
0.7.4.post1
0.7.5.post1
0.7.5.post2
0.8.0
0.8.0.post0
0.8.1
0.8.1.post0
0.8.2
0.8.2.post0
0.9.0
0.9.0.post2
0.9.0.post3
0.9.0.post4
0.9.0.post5
0.9.1
0.9.1.post0
0.9.1.post1
0.9.1.post2
1.0.0
1.0.0.post0
1.0.0.post1
1.0.0.post2
1.0.0.post3
1.0.1
1.0.2
1.0.2.post0
1.1.0
1.1.0rc0
1.1.1
1.10.0
1.10.0.post0
1.10.1
1.2
1.3
1.3.post0
1.3.post1
1.4
1.4.1
1.4.1.post0
1.4.1.post1
1.5.0
1.5.0.post0
1.6.0
1.7.0
1.7.1
1.7.2
1.7.3
1.8.0
1.8.1
1.8.2
1.8.2.post0
1.8.2.post1
1.9.0
1.9.1
1.9.1.post0
1.9.2
1.9.2.post0
Fixed in
1.11.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-23633
GHSA-fq23-g58m-799r
PYSEC-2024-128
Jan 24, 2024
Cross-site Scripting Vulnerability on Data Import
4.7
/ 10
Medium
Network
Low
None
Required
Changed
Low
None
None
IntroductionThis write-up describes a vulnerability found in Label Studio, a popular open source data labeling tool. The vulnerability affects all versions of Label Studio prior to OverviewLabel Studio had a remote import feature allowed users to import data from a remote web source, that was downloaded and could be viewed on the website. This feature could had been abused to download a HTML file that executed malicious JavaScript code in the context of the Label Studio website. DescriptionThe following code snippet in Label Studio showed that is a URL passed the SSRF verification checks, the contents of the file would be downloaded using the filename in the URL.
The downloaded file path could then be retrieved by sending a request to
Since the Proof of ConceptBelow were the steps to recreate this issue:
ImpactExecuting arbitrary JavaScript could result in an attacker performing malicious actions on Label Studio users if they visit the crafted avatar image. For an example, an attacker can craft a JavaScript payload that adds a new Django Super Administrator user if a Django administrator visits the image. Remediation Advice
Discovered
Affected versions
0.4.1
0.4.2
0.4.3
0.4.4
0.4.4.post1
0.4.4.post2
0.4.5
0.4.6
0.4.6.post1
0.4.6.post2
0.4.7
0.4.8
+ 66 more Show less
0.5.0
0.5.1
0.6.0
0.6.1
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.4.post0
0.7.4.post1
0.7.5.post1
0.7.5.post2
0.8.0
0.8.0.post0
0.8.1
0.8.1.post0
0.8.2
0.8.2.post0
0.9.0
0.9.0.post2
0.9.0.post3
0.9.0.post4
0.9.0.post5
0.9.1
0.9.1.post0
0.9.1.post1
0.9.1.post2
1.0.0
1.0.0.post0
1.0.0.post1
1.0.0.post2
1.0.0.post3
1.0.1
1.0.2
1.0.2.post0
1.1.0
1.1.0rc0
1.1.1
1.10.0
1.10.0.post0
1.2
1.3
1.3.post0
1.3.post1
1.4
1.4.1
1.4.1.post0
1.4.1.post1
1.5.0
1.5.0.post0
1.6.0
1.7.0
1.7.1
1.7.2
1.7.3
1.8.0
1.8.1
1.8.2
1.8.2.post0
1.8.2.post1
1.9.0
1.9.1
1.9.1.post0
1.9.2
1.9.2.post0
Fixed in
1.10.1
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2023-47115
GHSA-q68h-xwq5-mm7x
PYSEC-2024-126
Jan 24, 2024
Cross-site Scripting Vulnerability on Avatar Upload
7.1
/ 10
High
Network
Low
None
Required
Changed
Low
Low
Low
IntroductionThis write-up describes a vulnerability found in Label Studio, a popular open source data labeling tool. The vulnerability affects all versions of Label Studio prior to OverviewLabel Studio has a cross-site scripting (XSS) vulnerability that could be exploited when an authenticated user uploads a crafted image file for their avatar that gets rendered as a HTML file on the website. DescriptionThe following code snippet in Label Studio shows that the only verification check is that the file is an image by extracting the dimensions from the file.
Label Studio serves avatar images using Django's built-in
The issue with the Django Proof of ConceptBelow are the steps to reproduce this issue and execute JavaScript code in the context of the Label Studio website.
ImpactExecuting arbitrary JavaScript could result in an attacker performing malicious actions on Label Studio users if they visit the crafted avatar image. For an example, an attacker can craft a JavaScript payload that adds a new Django Super Administrator user if a Django administrator visits the image. Remediation Advice
Discovered
Affected versions
0.4.1
0.4.2
0.4.3
0.4.4
0.4.4.post1
0.4.4.post2
0.4.5
0.4.6
0.4.6.post1
0.4.6.post2
0.4.7
0.4.8
+ 62 more Show less
0.5.0
0.5.1
0.6.0
0.6.1
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.4.post0
0.7.4.post1
0.7.5.post1
0.7.5.post2
0.8.0
0.8.0.post0
0.8.1
0.8.1.post0
0.8.2
0.8.2.post0
0.9.0
0.9.0.post2
0.9.0.post3
0.9.0.post4
0.9.0.post5
0.9.1
0.9.1.post0
0.9.1.post1
0.9.1.post2
1.0.0
1.0.0.post0
1.0.0.post1
1.0.0.post2
1.0.0.post3
1.0.1
1.0.2
1.0.2.post0
1.1.0
1.1.0rc0
1.1.1
1.2
1.3
1.3.post0
1.3.post1
1.4
1.4.1
1.4.1.post0
1.4.1.post1
1.5.0
1.5.0.post0
1.6.0
1.7.0
1.7.1
1.7.2
1.7.3
1.8.0
1.8.1
1.8.2
1.8.2.post0
1.8.2.post1
1.9.0
1.9.1
1.9.1.post0
Fixed in
1.9.2
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2023-47117
GHSA-6hjj-gq77-j4qw
PYSEC-2023-275
Nov 14, 2023
Label Studio Object Relational Mapper Leak Vulnerability in Filtering Task
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
IntroductionThis write-up describes a vulnerability found in Label Studio, a popular open source data labeling tool. The vulnerability affects all versions of Label Studio prior to OverviewIn all current versions of Label Studio, the application allows users to insecurely set filters for filtering tasks. An attacker can construct a filter chain to filter tasks based on sensitive fields for all user accounts on the platform by exploiting Django's Object Relational Mapper (ORM). Since the results of query can be manipulated by the ORM filter, an attacker can leak these sensitive fields character by character. For an example, the following filter chain will task results by the password hash of an account on Label Studio.
For consistency, this type of vulnerability will be termed as ORM Leak in the rest of this disclosure. In addition, Label Studio had a hard coded secret key that an attacker can use to forge a session token of any user by exploiting this ORM Leak vulnerability to leak account password hashes. DescriptionThe following code snippet from the
These
The
The following code snippet of the
Finally, the
Proof of ConceptBelow are the steps to exploit about how to exploit this vulnerability to leak the password hash of an account on Label Studio.
The following example GIF demonstrates exploiting this ORM Leak vulnerability to retrieve the password hash
ImpactThis vulnerability can be exploited to completely compromise the confidentiality of highly sensitive account information, such as account password hashes. For all versions Remediation Advice
Discovered
| ||
1.2
minor
12 CVEs
CVE-2026-22033
PYSEC-2026-1502
GHSA-2mq9-hm29-8qch
Jul 07, 2026
Label Studio is vulnerable to full account takeover by chaining Stored XSS + IDOR in User Profile via custom_hotkeys field
Critical
Network
Low
Low
None
PrologueThese vulnerabilities have been found and chained by DCODX-AI. Validation of the exploit chain has been confirmed manually. SummaryA persistent stored cross-site scripting (XSS) vulnerability exists in the custom_hotkeys functionality of the application. An authenticated attacker (or one who can trick a user/administrator into updating their custom_hotkeys) can inject JavaScript code that executes in other users’ browsers when those users load any page using the DetailsWithin
Here, user.custom_hotkeys is run through json_dumps_ensure_ascii (in In
The serializer allows
When another user loads a page using templates/base.html (for example PoC
Example request
Example response
ImpactExploitation impact:
Who is impacted:
Affected versions
0.4.1
0.4.2
0.4.3
0.4.4
0.4.4.post1
0.4.4.post2
0.4.5
0.4.6
0.4.6.post1
0.4.6.post2
0.4.7
0.4.8
+ 83 more Show less
0.5.0
0.5.1
0.6.0
0.6.1
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.4.post0
0.7.4.post1
0.7.5.post1
0.7.5.post2
0.8.0
0.8.0.post0
0.8.1
0.8.1.post0
0.8.2
0.8.2.post0
0.9.0
0.9.0.post2
0.9.0.post3
0.9.0.post4
0.9.0.post5
0.9.1
0.9.1.post0
0.9.1.post1
0.9.1.post2
1.0.0
1.0.0.post0
1.0.0.post1
1.0.0.post2
1.0.0.post3
1.0.1
1.0.2
1.0.2.post0
1.1.0
1.1.0rc0
1.1.1
1.10.0
1.10.0.post0
1.10.1
1.11.0
1.12.0
1.12.0.post0
1.12.1
1.13.0
1.13.1
1.14.0
1.14.0.post0
1.15.0
1.16.0
1.17.0
1.18.0
1.19.0
1.2
1.20.0
1.21.0
1.22.0
1.3
1.3.post0
1.3.post1
1.4
1.4.1
1.4.1.post0
1.4.1.post1
1.5.0
1.5.0.post0
1.6.0
1.7.0
1.7.1
1.7.2
1.7.3
1.8.0
1.8.1
1.8.2
1.8.2.post0
1.8.2.post1
1.9.0
1.9.1
1.9.1.post0
1.9.2
1.9.2.post0
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-25297
PYSEC-2026-1503
GHSA-m238-fmcw-wh58
Jul 07, 2026
Label Studio allows Server-Side Request Forgery in the S3 Storage Endpoint
8.6
/ 10
High
Network
Low
None
None
Changed
High
None
None
DescriptionLabel Studio's S3 storage integration feature contains a Server-Side Request Forgery (SSRF) vulnerability in its endpoint configuration. When creating an S3 storage connection, the application allows users to specify a custom S3 endpoint URL via the s3_endpoint parameter. This endpoint URL is passed directly to the boto3 AWS SDK without proper validation or restrictions on the protocol or destination. The vulnerability allows an attacker to make the application send HTTP requests to arbitrary internal services by specifying them as the S3 endpoint. When the storage sync operation is triggered, the application attempts to make S3 API calls to the specified endpoint, effectively making HTTP requests to the target service and returning the response in error messages. This SSRF vulnerability enables attackers to bypass network segmentation and access internal services that should not be accessible from the external network. The vulnerability is particularly severe because error messages from failed requests contain the full response body, allowing data exfiltration from internal services. Steps to reproduce
The application will attempt to connect to the specified endpoint URL as if it were an S3 service. When the request fails due to invalid S3 API responses, the error message will contain the raw response from the internal service, allowing access to internal resources. Mitigations
ImpactThis vulnerability has high severity as it allows authenticated users to make requests to arbitrary internal services from the application server, potentially exposing sensitive internal resources and bypassing network segmentation. The inclusion of response data in error messages makes this particularly effective for data exfiltration. Affected versions
0.4.1
0.4.2
0.4.3
0.4.4
0.4.4.post1
0.4.4.post2
0.4.5
0.4.6
0.4.6.post1
0.4.6.post2
0.4.7
0.4.8
+ 76 more Show less
0.5.0
0.5.1
0.6.0
0.6.1
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.4.post0
0.7.4.post1
0.7.5.post1
0.7.5.post2
0.8.0
0.8.0.post0
0.8.1
0.8.1.post0
0.8.2
0.8.2.post0
0.9.0
0.9.0.post2
0.9.0.post3
0.9.0.post4
0.9.0.post5
0.9.1
0.9.1.post0
0.9.1.post1
0.9.1.post2
1.0.0
1.0.0.post0
1.0.0.post1
1.0.0.post2
1.0.0.post3
1.0.1
1.0.2
1.0.2.post0
1.1.0
1.1.0rc0
1.1.1
1.10.0
1.10.0.post0
1.10.1
1.11.0
1.12.0
1.12.0.post0
1.12.1
1.13.0
1.13.1
1.14.0
1.14.0.post0
1.15.0
1.2
1.3
1.3.post0
1.3.post1
1.4
1.4.1
1.4.1.post0
1.4.1.post1
1.5.0
1.5.0.post0
1.6.0
1.7.0
1.7.1
1.7.2
1.7.3
1.8.0
1.8.1
1.8.2
1.8.2.post0
1.8.2.post1
1.9.0
1.9.1
1.9.1.post0
1.9.2
1.9.2.post0
Fixed in
1.16.0
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-25296
PYSEC-2026-1504
GHSA-wpq5-3366-mqw4
Jul 07, 2026
Label Studio allows Cross-Site Scripting (XSS) via GET request to `/projects/upload-example` endpoint
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
DescriptionLabel Studio's The vulnerability exists because the upload-example endpoint renders user-provided HTML content without proper sanitization on a GET request. This allows attackers to inject and execute arbitrary JavaScript in victims' browsers by getting them to visit a maliciously crafted URL. This is considered vulnerable because it enables attackers to execute JavaScript in victims' contexts, potentially allowing theft of sensitive data, session hijacking, or other malicious actions. Steps to reproduce
When executed, the payload causes the application to render an HTML page containing an img tag that fails to load, triggering the onerror event handler which executes base64-decoded JavaScript, demonstrating successful XSS execution in the victim's browser. Mitigations
ImpactThe vulnerability requires no special privileges and can be exploited by getting a victim to visit a crafted URL. The impact is high as it allows arbitrary JavaScript execution in victims' browsers, potentially exposing sensitive data or enabling account takeover through session theft. Affected versions
0.4.1
0.4.2
0.4.3
0.4.4
0.4.4.post1
0.4.4.post2
0.4.5
0.4.6
0.4.6.post1
0.4.6.post2
0.4.7
0.4.8
+ 76 more Show less
0.5.0
0.5.1
0.6.0
0.6.1
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.4.post0
0.7.4.post1
0.7.5.post1
0.7.5.post2
0.8.0
0.8.0.post0
0.8.1
0.8.1.post0
0.8.2
0.8.2.post0
0.9.0
0.9.0.post2
0.9.0.post3
0.9.0.post4
0.9.0.post5
0.9.1
0.9.1.post0
0.9.1.post1
0.9.1.post2
1.0.0
1.0.0.post0
1.0.0.post1
1.0.0.post2
1.0.0.post3
1.0.1
1.0.2
1.0.2.post0
1.1.0
1.1.0rc0
1.1.1
1.10.0
1.10.0.post0
1.10.1
1.11.0
1.12.0
1.12.0.post0
1.12.1
1.13.0
1.13.1
1.14.0
1.14.0.post0
1.15.0
1.2
1.3
1.3.post0
1.3.post1
1.4
1.4.1
1.4.1.post0
1.4.1.post1
1.5.0
1.5.0.post0
1.6.0
1.7.0
1.7.1
1.7.2
1.7.3
1.8.0
1.8.1
1.8.2
1.8.2.post0
1.8.2.post1
1.9.0
1.9.1
1.9.1.post0
1.9.2
1.9.2.post0
Fixed in
1.16.0
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-47783
GHSA-8jhr-wpcm-hh4h
PYSEC-2025-124
May 15, 2025
label-studio vulnerable to Cross-Site Scripting (Reflected) via the label_config parameter.
High
Network
Low
None
SummaryThe vulnerability allows an attacker to inject a malicious script into the context of a web page, which can lead to data theft, unauthorized actions on behalf of the user, and other attacks. DetailsThe vulnerability is reproducible when sending a properly formatted request to the
The vulnerability is specifically located in line 57, where HttpResponse is used.
PoCSend the following request after changing the
Or you can create a vulnerable HTML page by changing
Impact
Affected versions
0.4.1
0.4.2
0.4.3
0.4.4
0.4.4.post1
0.4.4.post2
0.4.5
0.4.6
0.4.6.post1
0.4.6.post2
0.4.7
0.4.8
+ 78 more Show less
0.5.0
0.5.1
0.6.0
0.6.1
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.4.post0
0.7.4.post1
0.7.5.post1
0.7.5.post2
0.8.0
0.8.0.post0
0.8.1
0.8.1.post0
0.8.2
0.8.2.post0
0.9.0
0.9.0.post2
0.9.0.post3
0.9.0.post4
0.9.0.post5
0.9.1
0.9.1.post0
0.9.1.post1
0.9.1.post2
1.0.0
1.0.0.post0
1.0.0.post1
1.0.0.post2
1.0.0.post3
1.0.1
1.0.2
1.0.2.post0
1.1.0
1.1.0rc0
1.1.1
1.10.0
1.10.0.post0
1.10.1
1.11.0
1.12.0
1.12.0.post0
1.12.1
1.13.0
1.13.1
1.14.0
1.14.0.post0
1.15.0
1.16.0
1.17.0
1.2
1.3
1.3.post0
1.3.post1
1.4
1.4.1
1.4.1.post0
1.4.1.post1
1.5.0
1.5.0.post0
1.6.0
1.7.0
1.7.1
1.7.2
1.7.3
1.8.0
1.8.1
1.8.2
1.8.2.post0
1.8.2.post1
1.9.0
1.9.1
1.9.1.post0
1.9.2
1.9.2.post0
Fixed in
1.18.0
References
Updated Jun 06, 2026 · Source: OSV.dev
CVE-2024-26152
PYSEC-2024-249
GHSA-6xv9-957j-qfhg
Feb 22, 2024
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
SummaryOn all Label Studio versions prior to 1.11.0, data imported via file upload feature is not properly sanitized prior to being rendered within a DetailsNeed permission to use the "data import" function. This was reproduced on Label Studio 1.10.1. PoC
The following are the contents of the files used in the PoC
ImpactMalicious scripts can be injected into the code, and when linked with vulnerabilities such as CSRF, it can cause even greater damage. In particular, It can become a source of further attacks, especially when linked to social engineering. Affected versions
0.4.1
0.4.2
0.4.3
0.4.4
0.4.4.post1
0.4.4.post2
0.4.5
0.4.6
0.4.6.post1
0.4.6.post2
0.4.7
0.4.8
+ 113 more Show less
0.5.0
0.5.1
0.6.0
0.6.1
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.4.post0
0.7.4.post1
0.7.5.post1
0.7.5.post2
0.8.0
0.8.0.post0
0.8.1
0.8.1.post0
0.8.2
0.8.2.post0
0.9.0
0.9.0.post2
0.9.0.post3
0.9.0.post4
0.9.0.post5
0.9.1
0.9.1.post0
0.9.1.post1
0.9.1.post2
1.0.0
1.0.0.post0
1.0.0.post1
1.0.0.post2
1.0.0.post3
1.0.1
1.0.2
1.0.2.post0
1.1.0
1.1.0rc0
1.1.1
1.10.0
1.10.0.post0
1.10.1
1.2
1.3
1.3.post0
1.3.post1
1.4
1.4.1
1.4.1.post0
1.4.1.post1
1.5.0
1.5.0.post0
1.6.0
1.7.0
1.7.1
1.7.2
1.7.3
1.8.0
1.8.1
1.8.2
1.8.2.post0
1.8.2.post1
1.9.0
1.9.1
1.9.1.post0
1.9.2
1.9.2.post0
v1.4.1
v1.4.0
v1.3.0
v1.2.0
v1.1.1
v1.1.0
v1.0.2
v1.0.1
v1.0.0
v0.9.1.post1
v0.9.1.post0
v0.9.0.post5
v0.9.0.post4
v0.9.0.post3
v0.9.0
v0.8.2
v0.8.1
v0.8.0
v0.7.5.post0
v0.7.3
v0.7.2
v0.7.1
v0.7.0
v0.6.1
v0.6.0
v0.5.1
v0.4.8
v0.4.7
v0.4.6
v0.4.5
v0.4.4
v0.4.0
v0.3.0
v0.2.2
v.0.2.1-8
v.0.2.1-5
v.0.2.1-4
v.0.2.1-3
v.0.2.1-2
v.0.2.0
v.0.1.6
v.0.1.5
v.0.1.4
v.0.1.2
v.0.1.1
v.0.1.0
Fixed in
1.11.0
References
Updated Jun 10, 2026 · Source: OSV.dev
CVE-2023-47116
GHSA-p59w-9gqw-wj8r
PYSEC-2024-127
Jan 31, 2024
Label Studio SSRF on Import Bypassing `SSRF_PROTECTION_ENABLED` Protections
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
IntroductionThis write-up describes a vulnerability found in Label Studio, a popular open source data labeling tool. The vulnerability affects all versions of Label Studio prior to OverviewLabel Studio's SSRF protections that can be enabled by setting the DescriptionThe following
The
The issue here is the SSRF validation is only performed before the request is sent, and does not validate the destination IP address. Therefore, an attacker can either redirect the request or perform a DNS rebinding attack to bypass this protection. Proof of ConceptBoth the HTTP redirection and DNS rebinding methods for bypassing Label Studio's SSRF protections are explained below. HTTP RedirectionThe python
DNS Rebinding AttackDNS rebinding can bypass SSRF protections by resolving to an external IP address for the first resolution, but when the request is sent resolves to an internal IP address that is blocked. For an example, the domain ImpactSSRF vulnerabilities pose a significant risk on cloud environments, since instance credentials are managed by internal web APIs. An attacker can bypass Label Studio's SSRF protections to access internal web servers and partially compromise the confidentiality of those internal servers. Remediation Advice
Discovered
Affected versions
0.4.1
0.4.2
0.4.3
0.4.4
0.4.4.post1
0.4.4.post2
0.4.5
0.4.6
0.4.6.post1
0.4.6.post2
0.4.7
0.4.8
+ 67 more Show less
0.5.0
0.5.1
0.6.0
0.6.1
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.4.post0
0.7.4.post1
0.7.5.post1
0.7.5.post2
0.8.0
0.8.0.post0
0.8.1
0.8.1.post0
0.8.2
0.8.2.post0
0.9.0
0.9.0.post2
0.9.0.post3
0.9.0.post4
0.9.0.post5
0.9.1
0.9.1.post0
0.9.1.post1
0.9.1.post2
1.0.0
1.0.0.post0
1.0.0.post1
1.0.0.post2
1.0.0.post3
1.0.1
1.0.2
1.0.2.post0
1.1.0
1.1.0rc0
1.1.1
1.10.0
1.10.0.post0
1.10.1
1.2
1.3
1.3.post0
1.3.post1
1.4
1.4.1
1.4.1.post0
1.4.1.post1
1.5.0
1.5.0.post0
1.6.0
1.7.0
1.7.1
1.7.2
1.7.3
1.8.0
1.8.1
1.8.2
1.8.2.post0
1.8.2.post1
1.9.0
1.9.1
1.9.1.post0
1.9.2
1.9.2.post0
Fixed in
1.11.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-23633
GHSA-fq23-g58m-799r
PYSEC-2024-128
Jan 24, 2024
Cross-site Scripting Vulnerability on Data Import
4.7
/ 10
Medium
Network
Low
None
Required
Changed
Low
None
None
IntroductionThis write-up describes a vulnerability found in Label Studio, a popular open source data labeling tool. The vulnerability affects all versions of Label Studio prior to OverviewLabel Studio had a remote import feature allowed users to import data from a remote web source, that was downloaded and could be viewed on the website. This feature could had been abused to download a HTML file that executed malicious JavaScript code in the context of the Label Studio website. DescriptionThe following code snippet in Label Studio showed that is a URL passed the SSRF verification checks, the contents of the file would be downloaded using the filename in the URL.
The downloaded file path could then be retrieved by sending a request to
Since the Proof of ConceptBelow were the steps to recreate this issue:
ImpactExecuting arbitrary JavaScript could result in an attacker performing malicious actions on Label Studio users if they visit the crafted avatar image. For an example, an attacker can craft a JavaScript payload that adds a new Django Super Administrator user if a Django administrator visits the image. Remediation Advice
Discovered
Affected versions
0.4.1
0.4.2
0.4.3
0.4.4
0.4.4.post1
0.4.4.post2
0.4.5
0.4.6
0.4.6.post1
0.4.6.post2
0.4.7
0.4.8
+ 66 more Show less
0.5.0
0.5.1
0.6.0
0.6.1
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.4.post0
0.7.4.post1
0.7.5.post1
0.7.5.post2
0.8.0
0.8.0.post0
0.8.1
0.8.1.post0
0.8.2
0.8.2.post0
0.9.0
0.9.0.post2
0.9.0.post3
0.9.0.post4
0.9.0.post5
0.9.1
0.9.1.post0
0.9.1.post1
0.9.1.post2
1.0.0
1.0.0.post0
1.0.0.post1
1.0.0.post2
1.0.0.post3
1.0.1
1.0.2
1.0.2.post0
1.1.0
1.1.0rc0
1.1.1
1.10.0
1.10.0.post0
1.2
1.3
1.3.post0
1.3.post1
1.4
1.4.1
1.4.1.post0
1.4.1.post1
1.5.0
1.5.0.post0
1.6.0
1.7.0
1.7.1
1.7.2
1.7.3
1.8.0
1.8.1
1.8.2
1.8.2.post0
1.8.2.post1
1.9.0
1.9.1
1.9.1.post0
1.9.2
1.9.2.post0
Fixed in
1.10.1
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2023-47115
GHSA-q68h-xwq5-mm7x
PYSEC-2024-126
Jan 24, 2024
Cross-site Scripting Vulnerability on Avatar Upload
7.1
/ 10
High
Network
Low
None
Required
Changed
Low
Low
Low
IntroductionThis write-up describes a vulnerability found in Label Studio, a popular open source data labeling tool. The vulnerability affects all versions of Label Studio prior to OverviewLabel Studio has a cross-site scripting (XSS) vulnerability that could be exploited when an authenticated user uploads a crafted image file for their avatar that gets rendered as a HTML file on the website. DescriptionThe following code snippet in Label Studio shows that the only verification check is that the file is an image by extracting the dimensions from the file.
Label Studio serves avatar images using Django's built-in
The issue with the Django Proof of ConceptBelow are the steps to reproduce this issue and execute JavaScript code in the context of the Label Studio website.
ImpactExecuting arbitrary JavaScript could result in an attacker performing malicious actions on Label Studio users if they visit the crafted avatar image. For an example, an attacker can craft a JavaScript payload that adds a new Django Super Administrator user if a Django administrator visits the image. Remediation Advice
Discovered
Affected versions
0.4.1
0.4.2
0.4.3
0.4.4
0.4.4.post1
0.4.4.post2
0.4.5
0.4.6
0.4.6.post1
0.4.6.post2
0.4.7
0.4.8
+ 62 more Show less
0.5.0
0.5.1
0.6.0
0.6.1
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.4.post0
0.7.4.post1
0.7.5.post1
0.7.5.post2
0.8.0
0.8.0.post0
0.8.1
0.8.1.post0
0.8.2
0.8.2.post0
0.9.0
0.9.0.post2
0.9.0.post3
0.9.0.post4
0.9.0.post5
0.9.1
0.9.1.post0
0.9.1.post1
0.9.1.post2
1.0.0
1.0.0.post0
1.0.0.post1
1.0.0.post2
1.0.0.post3
1.0.1
1.0.2
1.0.2.post0
1.1.0
1.1.0rc0
1.1.1
1.2
1.3
1.3.post0
1.3.post1
1.4
1.4.1
1.4.1.post0
1.4.1.post1
1.5.0
1.5.0.post0
1.6.0
1.7.0
1.7.1
1.7.2
1.7.3
1.8.0
1.8.1
1.8.2
1.8.2.post0
1.8.2.post1
1.9.0
1.9.1
1.9.1.post0
Fixed in
1.9.2
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2023-47117
GHSA-6hjj-gq77-j4qw
PYSEC-2023-275
Nov 14, 2023
Label Studio Object Relational Mapper Leak Vulnerability in Filtering Task
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
IntroductionThis write-up describes a vulnerability found in Label Studio, a popular open source data labeling tool. The vulnerability affects all versions of Label Studio prior to OverviewIn all current versions of Label Studio, the application allows users to insecurely set filters for filtering tasks. An attacker can construct a filter chain to filter tasks based on sensitive fields for all user accounts on the platform by exploiting Django's Object Relational Mapper (ORM). Since the results of query can be manipulated by the ORM filter, an attacker can leak these sensitive fields character by character. For an example, the following filter chain will task results by the password hash of an account on Label Studio.
For consistency, this type of vulnerability will be termed as ORM Leak in the rest of this disclosure. In addition, Label Studio had a hard coded secret key that an attacker can use to forge a session token of any user by exploiting this ORM Leak vulnerability to leak account password hashes. DescriptionThe following code snippet from the
These
The
The following code snippet of the
Finally, the
Proof of ConceptBelow are the steps to exploit about how to exploit this vulnerability to leak the password hash of an account on Label Studio.
The following example GIF demonstrates exploiting this ORM Leak vulnerability to retrieve the password hash
ImpactThis vulnerability can be exploited to completely compromise the confidentiality of highly sensitive account information, such as account password hashes. For all versions Remediation Advice
Discovered
| ||
1.1.1
patch
12 CVEs
CVE-2026-22033
PYSEC-2026-1502
GHSA-2mq9-hm29-8qch
Jul 07, 2026
Label Studio is vulnerable to full account takeover by chaining Stored XSS + IDOR in User Profile via custom_hotkeys field
Critical
Network
Low
Low
None
PrologueThese vulnerabilities have been found and chained by DCODX-AI. Validation of the exploit chain has been confirmed manually. SummaryA persistent stored cross-site scripting (XSS) vulnerability exists in the custom_hotkeys functionality of the application. An authenticated attacker (or one who can trick a user/administrator into updating their custom_hotkeys) can inject JavaScript code that executes in other users’ browsers when those users load any page using the DetailsWithin
Here, user.custom_hotkeys is run through json_dumps_ensure_ascii (in In
The serializer allows
When another user loads a page using templates/base.html (for example PoC
Example request
Example response
ImpactExploitation impact:
Who is impacted:
Affected versions
0.4.1
0.4.2
0.4.3
0.4.4
0.4.4.post1
0.4.4.post2
0.4.5
0.4.6
0.4.6.post1
0.4.6.post2
0.4.7
0.4.8
+ 83 more Show less
0.5.0
0.5.1
0.6.0
0.6.1
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.4.post0
0.7.4.post1
0.7.5.post1
0.7.5.post2
0.8.0
0.8.0.post0
0.8.1
0.8.1.post0
0.8.2
0.8.2.post0
0.9.0
0.9.0.post2
0.9.0.post3
0.9.0.post4
0.9.0.post5
0.9.1
0.9.1.post0
0.9.1.post1
0.9.1.post2
1.0.0
1.0.0.post0
1.0.0.post1
1.0.0.post2
1.0.0.post3
1.0.1
1.0.2
1.0.2.post0
1.1.0
1.1.0rc0
1.1.1
1.10.0
1.10.0.post0
1.10.1
1.11.0
1.12.0
1.12.0.post0
1.12.1
1.13.0
1.13.1
1.14.0
1.14.0.post0
1.15.0
1.16.0
1.17.0
1.18.0
1.19.0
1.2
1.20.0
1.21.0
1.22.0
1.3
1.3.post0
1.3.post1
1.4
1.4.1
1.4.1.post0
1.4.1.post1
1.5.0
1.5.0.post0
1.6.0
1.7.0
1.7.1
1.7.2
1.7.3
1.8.0
1.8.1
1.8.2
1.8.2.post0
1.8.2.post1
1.9.0
1.9.1
1.9.1.post0
1.9.2
1.9.2.post0
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-25297
PYSEC-2026-1503
GHSA-m238-fmcw-wh58
Jul 07, 2026
Label Studio allows Server-Side Request Forgery in the S3 Storage Endpoint
8.6
/ 10
High
Network
Low
None
None
Changed
High
None
None
DescriptionLabel Studio's S3 storage integration feature contains a Server-Side Request Forgery (SSRF) vulnerability in its endpoint configuration. When creating an S3 storage connection, the application allows users to specify a custom S3 endpoint URL via the s3_endpoint parameter. This endpoint URL is passed directly to the boto3 AWS SDK without proper validation or restrictions on the protocol or destination. The vulnerability allows an attacker to make the application send HTTP requests to arbitrary internal services by specifying them as the S3 endpoint. When the storage sync operation is triggered, the application attempts to make S3 API calls to the specified endpoint, effectively making HTTP requests to the target service and returning the response in error messages. This SSRF vulnerability enables attackers to bypass network segmentation and access internal services that should not be accessible from the external network. The vulnerability is particularly severe because error messages from failed requests contain the full response body, allowing data exfiltration from internal services. Steps to reproduce
The application will attempt to connect to the specified endpoint URL as if it were an S3 service. When the request fails due to invalid S3 API responses, the error message will contain the raw response from the internal service, allowing access to internal resources. Mitigations
ImpactThis vulnerability has high severity as it allows authenticated users to make requests to arbitrary internal services from the application server, potentially exposing sensitive internal resources and bypassing network segmentation. The inclusion of response data in error messages makes this particularly effective for data exfiltration. Affected versions
0.4.1
0.4.2
0.4.3
0.4.4
0.4.4.post1
0.4.4.post2
0.4.5
0.4.6
0.4.6.post1
0.4.6.post2
0.4.7
0.4.8
+ 76 more Show less
0.5.0
0.5.1
0.6.0
0.6.1
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.4.post0
0.7.4.post1
0.7.5.post1
0.7.5.post2
0.8.0
0.8.0.post0
0.8.1
0.8.1.post0
0.8.2
0.8.2.post0
0.9.0
0.9.0.post2
0.9.0.post3
0.9.0.post4
0.9.0.post5
0.9.1
0.9.1.post0
0.9.1.post1
0.9.1.post2
1.0.0
1.0.0.post0
1.0.0.post1
1.0.0.post2
1.0.0.post3
1.0.1
1.0.2
1.0.2.post0
1.1.0
1.1.0rc0
1.1.1
1.10.0
1.10.0.post0
1.10.1
1.11.0
1.12.0
1.12.0.post0
1.12.1
1.13.0
1.13.1
1.14.0
1.14.0.post0
1.15.0
1.2
1.3
1.3.post0
1.3.post1
1.4
1.4.1
1.4.1.post0
1.4.1.post1
1.5.0
1.5.0.post0
1.6.0
1.7.0
1.7.1
1.7.2
1.7.3
1.8.0
1.8.1
1.8.2
1.8.2.post0
1.8.2.post1
1.9.0
1.9.1
1.9.1.post0
1.9.2
1.9.2.post0
Fixed in
1.16.0
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-25296
PYSEC-2026-1504
GHSA-wpq5-3366-mqw4
Jul 07, 2026
Label Studio allows Cross-Site Scripting (XSS) via GET request to `/projects/upload-example` endpoint
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
DescriptionLabel Studio's The vulnerability exists because the upload-example endpoint renders user-provided HTML content without proper sanitization on a GET request. This allows attackers to inject and execute arbitrary JavaScript in victims' browsers by getting them to visit a maliciously crafted URL. This is considered vulnerable because it enables attackers to execute JavaScript in victims' contexts, potentially allowing theft of sensitive data, session hijacking, or other malicious actions. Steps to reproduce
When executed, the payload causes the application to render an HTML page containing an img tag that fails to load, triggering the onerror event handler which executes base64-decoded JavaScript, demonstrating successful XSS execution in the victim's browser. Mitigations
ImpactThe vulnerability requires no special privileges and can be exploited by getting a victim to visit a crafted URL. The impact is high as it allows arbitrary JavaScript execution in victims' browsers, potentially exposing sensitive data or enabling account takeover through session theft. Affected versions
0.4.1
0.4.2
0.4.3
0.4.4
0.4.4.post1
0.4.4.post2
0.4.5
0.4.6
0.4.6.post1
0.4.6.post2
0.4.7
0.4.8
+ 76 more Show less
0.5.0
0.5.1
0.6.0
0.6.1
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.4.post0
0.7.4.post1
0.7.5.post1
0.7.5.post2
0.8.0
0.8.0.post0
0.8.1
0.8.1.post0
0.8.2
0.8.2.post0
0.9.0
0.9.0.post2
0.9.0.post3
0.9.0.post4
0.9.0.post5
0.9.1
0.9.1.post0
0.9.1.post1
0.9.1.post2
1.0.0
1.0.0.post0
1.0.0.post1
1.0.0.post2
1.0.0.post3
1.0.1
1.0.2
1.0.2.post0
1.1.0
1.1.0rc0
1.1.1
1.10.0
1.10.0.post0
1.10.1
1.11.0
1.12.0
1.12.0.post0
1.12.1
1.13.0
1.13.1
1.14.0
1.14.0.post0
1.15.0
1.2
1.3
1.3.post0
1.3.post1
1.4
1.4.1
1.4.1.post0
1.4.1.post1
1.5.0
1.5.0.post0
1.6.0
1.7.0
1.7.1
1.7.2
1.7.3
1.8.0
1.8.1
1.8.2
1.8.2.post0
1.8.2.post1
1.9.0
1.9.1
1.9.1.post0
1.9.2
1.9.2.post0
Fixed in
1.16.0
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-47783
GHSA-8jhr-wpcm-hh4h
PYSEC-2025-124
May 15, 2025
label-studio vulnerable to Cross-Site Scripting (Reflected) via the label_config parameter.
High
Network
Low
None
SummaryThe vulnerability allows an attacker to inject a malicious script into the context of a web page, which can lead to data theft, unauthorized actions on behalf of the user, and other attacks. DetailsThe vulnerability is reproducible when sending a properly formatted request to the
The vulnerability is specifically located in line 57, where HttpResponse is used.
PoCSend the following request after changing the
Or you can create a vulnerable HTML page by changing
Impact
Affected versions
0.4.1
0.4.2
0.4.3
0.4.4
0.4.4.post1
0.4.4.post2
0.4.5
0.4.6
0.4.6.post1
0.4.6.post2
0.4.7
0.4.8
+ 78 more Show less
0.5.0
0.5.1
0.6.0
0.6.1
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.4.post0
0.7.4.post1
0.7.5.post1
0.7.5.post2
0.8.0
0.8.0.post0
0.8.1
0.8.1.post0
0.8.2
0.8.2.post0
0.9.0
0.9.0.post2
0.9.0.post3
0.9.0.post4
0.9.0.post5
0.9.1
0.9.1.post0
0.9.1.post1
0.9.1.post2
1.0.0
1.0.0.post0
1.0.0.post1
1.0.0.post2
1.0.0.post3
1.0.1
1.0.2
1.0.2.post0
1.1.0
1.1.0rc0
1.1.1
1.10.0
1.10.0.post0
1.10.1
1.11.0
1.12.0
1.12.0.post0
1.12.1
1.13.0
1.13.1
1.14.0
1.14.0.post0
1.15.0
1.16.0
1.17.0
1.2
1.3
1.3.post0
1.3.post1
1.4
1.4.1
1.4.1.post0
1.4.1.post1
1.5.0
1.5.0.post0
1.6.0
1.7.0
1.7.1
1.7.2
1.7.3
1.8.0
1.8.1
1.8.2
1.8.2.post0
1.8.2.post1
1.9.0
1.9.1
1.9.1.post0
1.9.2
1.9.2.post0
Fixed in
1.18.0
References
Updated Jun 06, 2026 · Source: OSV.dev
CVE-2024-26152
PYSEC-2024-249
GHSA-6xv9-957j-qfhg
Feb 22, 2024
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
SummaryOn all Label Studio versions prior to 1.11.0, data imported via file upload feature is not properly sanitized prior to being rendered within a DetailsNeed permission to use the "data import" function. This was reproduced on Label Studio 1.10.1. PoC
The following are the contents of the files used in the PoC
ImpactMalicious scripts can be injected into the code, and when linked with vulnerabilities such as CSRF, it can cause even greater damage. In particular, It can become a source of further attacks, especially when linked to social engineering. Affected versions
0.4.1
0.4.2
0.4.3
0.4.4
0.4.4.post1
0.4.4.post2
0.4.5
0.4.6
0.4.6.post1
0.4.6.post2
0.4.7
0.4.8
+ 113 more Show less
0.5.0
0.5.1
0.6.0
0.6.1
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.4.post0
0.7.4.post1
0.7.5.post1
0.7.5.post2
0.8.0
0.8.0.post0
0.8.1
0.8.1.post0
0.8.2
0.8.2.post0
0.9.0
0.9.0.post2
0.9.0.post3
0.9.0.post4
0.9.0.post5
0.9.1
0.9.1.post0
0.9.1.post1
0.9.1.post2
1.0.0
1.0.0.post0
1.0.0.post1
1.0.0.post2
1.0.0.post3
1.0.1
1.0.2
1.0.2.post0
1.1.0
1.1.0rc0
1.1.1
1.10.0
1.10.0.post0
1.10.1
1.2
1.3
1.3.post0
1.3.post1
1.4
1.4.1
1.4.1.post0
1.4.1.post1
1.5.0
1.5.0.post0
1.6.0
1.7.0
1.7.1
1.7.2
1.7.3
1.8.0
1.8.1
1.8.2
1.8.2.post0
1.8.2.post1
1.9.0
1.9.1
1.9.1.post0
1.9.2
1.9.2.post0
v1.4.1
v1.4.0
v1.3.0
v1.2.0
v1.1.1
v1.1.0
v1.0.2
v1.0.1
v1.0.0
v0.9.1.post1
v0.9.1.post0
v0.9.0.post5
v0.9.0.post4
v0.9.0.post3
v0.9.0
v0.8.2
v0.8.1
v0.8.0
v0.7.5.post0
v0.7.3
v0.7.2
v0.7.1
v0.7.0
v0.6.1
v0.6.0
v0.5.1
v0.4.8
v0.4.7
v0.4.6
v0.4.5
v0.4.4
v0.4.0
v0.3.0
v0.2.2
v.0.2.1-8
v.0.2.1-5
v.0.2.1-4
v.0.2.1-3
v.0.2.1-2
v.0.2.0
v.0.1.6
v.0.1.5
v.0.1.4
v.0.1.2
v.0.1.1
v.0.1.0
Fixed in
1.11.0
References
Updated Jun 10, 2026 · Source: OSV.dev
CVE-2023-47116
GHSA-p59w-9gqw-wj8r
PYSEC-2024-127
Jan 31, 2024
Label Studio SSRF on Import Bypassing `SSRF_PROTECTION_ENABLED` Protections
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
IntroductionThis write-up describes a vulnerability found in Label Studio, a popular open source data labeling tool. The vulnerability affects all versions of Label Studio prior to OverviewLabel Studio's SSRF protections that can be enabled by setting the DescriptionThe following
The
The issue here is the SSRF validation is only performed before the request is sent, and does not validate the destination IP address. Therefore, an attacker can either redirect the request or perform a DNS rebinding attack to bypass this protection. Proof of ConceptBoth the HTTP redirection and DNS rebinding methods for bypassing Label Studio's SSRF protections are explained below. HTTP RedirectionThe python
DNS Rebinding AttackDNS rebinding can bypass SSRF protections by resolving to an external IP address for the first resolution, but when the request is sent resolves to an internal IP address that is blocked. For an example, the domain ImpactSSRF vulnerabilities pose a significant risk on cloud environments, since instance credentials are managed by internal web APIs. An attacker can bypass Label Studio's SSRF protections to access internal web servers and partially compromise the confidentiality of those internal servers. Remediation Advice
Discovered
Affected versions
0.4.1
0.4.2
0.4.3
0.4.4
0.4.4.post1
0.4.4.post2
0.4.5
0.4.6
0.4.6.post1
0.4.6.post2
0.4.7
0.4.8
+ 67 more Show less
0.5.0
0.5.1
0.6.0
0.6.1
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.4.post0
0.7.4.post1
0.7.5.post1
0.7.5.post2
0.8.0
0.8.0.post0
0.8.1
0.8.1.post0
0.8.2
0.8.2.post0
0.9.0
0.9.0.post2
0.9.0.post3
0.9.0.post4
0.9.0.post5
0.9.1
0.9.1.post0
0.9.1.post1
0.9.1.post2
1.0.0
1.0.0.post0
1.0.0.post1
1.0.0.post2
1.0.0.post3
1.0.1
1.0.2
1.0.2.post0
1.1.0
1.1.0rc0
1.1.1
1.10.0
1.10.0.post0
1.10.1
1.2
1.3
1.3.post0
1.3.post1
1.4
1.4.1
1.4.1.post0
1.4.1.post1
1.5.0
1.5.0.post0
1.6.0
1.7.0
1.7.1
1.7.2
1.7.3
1.8.0
1.8.1
1.8.2
1.8.2.post0
1.8.2.post1
1.9.0
1.9.1
1.9.1.post0
1.9.2
1.9.2.post0
Fixed in
1.11.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-23633
GHSA-fq23-g58m-799r
PYSEC-2024-128
Jan 24, 2024
Cross-site Scripting Vulnerability on Data Import
4.7
/ 10
Medium
Network
Low
None
Required
Changed
Low
None
None
IntroductionThis write-up describes a vulnerability found in Label Studio, a popular open source data labeling tool. The vulnerability affects all versions of Label Studio prior to OverviewLabel Studio had a remote import feature allowed users to import data from a remote web source, that was downloaded and could be viewed on the website. This feature could had been abused to download a HTML file that executed malicious JavaScript code in the context of the Label Studio website. DescriptionThe following code snippet in Label Studio showed that is a URL passed the SSRF verification checks, the contents of the file would be downloaded using the filename in the URL.
The downloaded file path could then be retrieved by sending a request to
Since the Proof of ConceptBelow were the steps to recreate this issue:
ImpactExecuting arbitrary JavaScript could result in an attacker performing malicious actions on Label Studio users if they visit the crafted avatar image. For an example, an attacker can craft a JavaScript payload that adds a new Django Super Administrator user if a Django administrator visits the image. Remediation Advice
Discovered
Affected versions
0.4.1
0.4.2
0.4.3
0.4.4
0.4.4.post1
0.4.4.post2
0.4.5
0.4.6
0.4.6.post1
0.4.6.post2
0.4.7
0.4.8
+ 66 more Show less
0.5.0
0.5.1
0.6.0
0.6.1
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.4.post0
0.7.4.post1
0.7.5.post1
0.7.5.post2
0.8.0
0.8.0.post0
0.8.1
0.8.1.post0
0.8.2
0.8.2.post0
0.9.0
0.9.0.post2
0.9.0.post3
0.9.0.post4
0.9.0.post5
0.9.1
0.9.1.post0
0.9.1.post1
0.9.1.post2
1.0.0
1.0.0.post0
1.0.0.post1
1.0.0.post2
1.0.0.post3
1.0.1
1.0.2
1.0.2.post0
1.1.0
1.1.0rc0
1.1.1
1.10.0
1.10.0.post0
1.2
1.3
1.3.post0
1.3.post1
1.4
1.4.1
1.4.1.post0
1.4.1.post1
1.5.0
1.5.0.post0
1.6.0
1.7.0
1.7.1
1.7.2
1.7.3
1.8.0
1.8.1
1.8.2
1.8.2.post0
1.8.2.post1
1.9.0
1.9.1
1.9.1.post0
1.9.2
1.9.2.post0
Fixed in
1.10.1
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2023-47115
GHSA-q68h-xwq5-mm7x
PYSEC-2024-126
Jan 24, 2024
Cross-site Scripting Vulnerability on Avatar Upload
7.1
/ 10
High
Network
Low
None
Required
Changed
Low
Low
Low
IntroductionThis write-up describes a vulnerability found in Label Studio, a popular open source data labeling tool. The vulnerability affects all versions of Label Studio prior to OverviewLabel Studio has a cross-site scripting (XSS) vulnerability that could be exploited when an authenticated user uploads a crafted image file for their avatar that gets rendered as a HTML file on the website. DescriptionThe following code snippet in Label Studio shows that the only verification check is that the file is an image by extracting the dimensions from the file.
Label Studio serves avatar images using Django's built-in
The issue with the Django Proof of ConceptBelow are the steps to reproduce this issue and execute JavaScript code in the context of the Label Studio website.
ImpactExecuting arbitrary JavaScript could result in an attacker performing malicious actions on Label Studio users if they visit the crafted avatar image. For an example, an attacker can craft a JavaScript payload that adds a new Django Super Administrator user if a Django administrator visits the image. Remediation Advice
Discovered
Affected versions
0.4.1
0.4.2
0.4.3
0.4.4
0.4.4.post1
0.4.4.post2
0.4.5
0.4.6
0.4.6.post1
0.4.6.post2
0.4.7
0.4.8
+ 62 more Show less
0.5.0
0.5.1
0.6.0
0.6.1
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.4.post0
0.7.4.post1
0.7.5.post1
0.7.5.post2
0.8.0
0.8.0.post0
0.8.1
0.8.1.post0
0.8.2
0.8.2.post0
0.9.0
0.9.0.post2
0.9.0.post3
0.9.0.post4
0.9.0.post5
0.9.1
0.9.1.post0
0.9.1.post1
0.9.1.post2
1.0.0
1.0.0.post0
1.0.0.post1
1.0.0.post2
1.0.0.post3
1.0.1
1.0.2
1.0.2.post0
1.1.0
1.1.0rc0
1.1.1
1.2
1.3
1.3.post0
1.3.post1
1.4
1.4.1
1.4.1.post0
1.4.1.post1
1.5.0
1.5.0.post0
1.6.0
1.7.0
1.7.1
1.7.2
1.7.3
1.8.0
1.8.1
1.8.2
1.8.2.post0
1.8.2.post1
1.9.0
1.9.1
1.9.1.post0
Fixed in
1.9.2
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2023-47117
GHSA-6hjj-gq77-j4qw
PYSEC-2023-275
Nov 14, 2023
Label Studio Object Relational Mapper Leak Vulnerability in Filtering Task
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
IntroductionThis write-up describes a vulnerability found in Label Studio, a popular open source data labeling tool. The vulnerability affects all versions of Label Studio prior to OverviewIn all current versions of Label Studio, the application allows users to insecurely set filters for filtering tasks. An attacker can construct a filter chain to filter tasks based on sensitive fields for all user accounts on the platform by exploiting Django's Object Relational Mapper (ORM). Since the results of query can be manipulated by the ORM filter, an attacker can leak these sensitive fields character by character. For an example, the following filter chain will task results by the password hash of an account on Label Studio.
For consistency, this type of vulnerability will be termed as ORM Leak in the rest of this disclosure. In addition, Label Studio had a hard coded secret key that an attacker can use to forge a session token of any user by exploiting this ORM Leak vulnerability to leak account password hashes. DescriptionThe following code snippet from the
These
The
The following code snippet of the
Finally, the
Proof of ConceptBelow are the steps to exploit about how to exploit this vulnerability to leak the password hash of an account on Label Studio.
The following example GIF demonstrates exploiting this ORM Leak vulnerability to retrieve the password hash
ImpactThis vulnerability can be exploited to completely compromise the confidentiality of highly sensitive account information, such as account password hashes. For all versions Remediation Advice
Discovered
| ||
1.1.0
minor
12 CVEs
CVE-2026-22033
PYSEC-2026-1502
GHSA-2mq9-hm29-8qch
Jul 07, 2026
Label Studio is vulnerable to full account takeover by chaining Stored XSS + IDOR in User Profile via custom_hotkeys field
Critical
Network
Low
Low
None
PrologueThese vulnerabilities have been found and chained by DCODX-AI. Validation of the exploit chain has been confirmed manually. SummaryA persistent stored cross-site scripting (XSS) vulnerability exists in the custom_hotkeys functionality of the application. An authenticated attacker (or one who can trick a user/administrator into updating their custom_hotkeys) can inject JavaScript code that executes in other users’ browsers when those users load any page using the DetailsWithin
Here, user.custom_hotkeys is run through json_dumps_ensure_ascii (in In
The serializer allows
When another user loads a page using templates/base.html (for example PoC
Example request
Example response
ImpactExploitation impact:
Who is impacted:
Affected versions
0.4.1
0.4.2
0.4.3
0.4.4
0.4.4.post1
0.4.4.post2
0.4.5
0.4.6
0.4.6.post1
0.4.6.post2
0.4.7
0.4.8
+ 83 more Show less
0.5.0
0.5.1
0.6.0
0.6.1
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.4.post0
0.7.4.post1
0.7.5.post1
0.7.5.post2
0.8.0
0.8.0.post0
0.8.1
0.8.1.post0
0.8.2
0.8.2.post0
0.9.0
0.9.0.post2
0.9.0.post3
0.9.0.post4
0.9.0.post5
0.9.1
0.9.1.post0
0.9.1.post1
0.9.1.post2
1.0.0
1.0.0.post0
1.0.0.post1
1.0.0.post2
1.0.0.post3
1.0.1
1.0.2
1.0.2.post0
1.1.0
1.1.0rc0
1.1.1
1.10.0
1.10.0.post0
1.10.1
1.11.0
1.12.0
1.12.0.post0
1.12.1
1.13.0
1.13.1
1.14.0
1.14.0.post0
1.15.0
1.16.0
1.17.0
1.18.0
1.19.0
1.2
1.20.0
1.21.0
1.22.0
1.3
1.3.post0
1.3.post1
1.4
1.4.1
1.4.1.post0
1.4.1.post1
1.5.0
1.5.0.post0
1.6.0
1.7.0
1.7.1
1.7.2
1.7.3
1.8.0
1.8.1
1.8.2
1.8.2.post0
1.8.2.post1
1.9.0
1.9.1
1.9.1.post0
1.9.2
1.9.2.post0
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-25297
PYSEC-2026-1503
GHSA-m238-fmcw-wh58
Jul 07, 2026
Label Studio allows Server-Side Request Forgery in the S3 Storage Endpoint
8.6
/ 10
High
Network
Low
None
None
Changed
High
None
None
DescriptionLabel Studio's S3 storage integration feature contains a Server-Side Request Forgery (SSRF) vulnerability in its endpoint configuration. When creating an S3 storage connection, the application allows users to specify a custom S3 endpoint URL via the s3_endpoint parameter. This endpoint URL is passed directly to the boto3 AWS SDK without proper validation or restrictions on the protocol or destination. The vulnerability allows an attacker to make the application send HTTP requests to arbitrary internal services by specifying them as the S3 endpoint. When the storage sync operation is triggered, the application attempts to make S3 API calls to the specified endpoint, effectively making HTTP requests to the target service and returning the response in error messages. This SSRF vulnerability enables attackers to bypass network segmentation and access internal services that should not be accessible from the external network. The vulnerability is particularly severe because error messages from failed requests contain the full response body, allowing data exfiltration from internal services. Steps to reproduce
The application will attempt to connect to the specified endpoint URL as if it were an S3 service. When the request fails due to invalid S3 API responses, the error message will contain the raw response from the internal service, allowing access to internal resources. Mitigations
ImpactThis vulnerability has high severity as it allows authenticated users to make requests to arbitrary internal services from the application server, potentially exposing sensitive internal resources and bypassing network segmentation. The inclusion of response data in error messages makes this particularly effective for data exfiltration. Affected versions
0.4.1
0.4.2
0.4.3
0.4.4
0.4.4.post1
0.4.4.post2
0.4.5
0.4.6
0.4.6.post1
0.4.6.post2
0.4.7
0.4.8
+ 76 more Show less
0.5.0
0.5.1
0.6.0
0.6.1
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.4.post0
0.7.4.post1
0.7.5.post1
0.7.5.post2
0.8.0
0.8.0.post0
0.8.1
0.8.1.post0
0.8.2
0.8.2.post0
0.9.0
0.9.0.post2
0.9.0.post3
0.9.0.post4
0.9.0.post5
0.9.1
0.9.1.post0
0.9.1.post1
0.9.1.post2
1.0.0
1.0.0.post0
1.0.0.post1
1.0.0.post2
1.0.0.post3
1.0.1
1.0.2
1.0.2.post0
1.1.0
1.1.0rc0
1.1.1
1.10.0
1.10.0.post0
1.10.1
1.11.0
1.12.0
1.12.0.post0
1.12.1
1.13.0
1.13.1
1.14.0
1.14.0.post0
1.15.0
1.2
1.3
1.3.post0
1.3.post1
1.4
1.4.1
1.4.1.post0
1.4.1.post1
1.5.0
1.5.0.post0
1.6.0
1.7.0
1.7.1
1.7.2
1.7.3
1.8.0
1.8.1
1.8.2
1.8.2.post0
1.8.2.post1
1.9.0
1.9.1
1.9.1.post0
1.9.2
1.9.2.post0
Fixed in
1.16.0
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-25296
PYSEC-2026-1504
GHSA-wpq5-3366-mqw4
Jul 07, 2026
Label Studio allows Cross-Site Scripting (XSS) via GET request to `/projects/upload-example` endpoint
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
DescriptionLabel Studio's The vulnerability exists because the upload-example endpoint renders user-provided HTML content without proper sanitization on a GET request. This allows attackers to inject and execute arbitrary JavaScript in victims' browsers by getting them to visit a maliciously crafted URL. This is considered vulnerable because it enables attackers to execute JavaScript in victims' contexts, potentially allowing theft of sensitive data, session hijacking, or other malicious actions. Steps to reproduce
When executed, the payload causes the application to render an HTML page containing an img tag that fails to load, triggering the onerror event handler which executes base64-decoded JavaScript, demonstrating successful XSS execution in the victim's browser. Mitigations
ImpactThe vulnerability requires no special privileges and can be exploited by getting a victim to visit a crafted URL. The impact is high as it allows arbitrary JavaScript execution in victims' browsers, potentially exposing sensitive data or enabling account takeover through session theft. Affected versions
0.4.1
0.4.2
0.4.3
0.4.4
0.4.4.post1
0.4.4.post2
0.4.5
0.4.6
0.4.6.post1
0.4.6.post2
0.4.7
0.4.8
+ 76 more Show less
0.5.0
0.5.1
0.6.0
0.6.1
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.4.post0
0.7.4.post1
0.7.5.post1
0.7.5.post2
0.8.0
0.8.0.post0
0.8.1
0.8.1.post0
0.8.2
0.8.2.post0
0.9.0
0.9.0.post2
0.9.0.post3
0.9.0.post4
0.9.0.post5
0.9.1
0.9.1.post0
0.9.1.post1
0.9.1.post2
1.0.0
1.0.0.post0
1.0.0.post1
1.0.0.post2
1.0.0.post3
1.0.1
1.0.2
1.0.2.post0
1.1.0
1.1.0rc0
1.1.1
1.10.0
1.10.0.post0
1.10.1
1.11.0
1.12.0
1.12.0.post0
1.12.1
1.13.0
1.13.1
1.14.0
1.14.0.post0
1.15.0
1.2
1.3
1.3.post0
1.3.post1
1.4
1.4.1
1.4.1.post0
1.4.1.post1
1.5.0
1.5.0.post0
1.6.0
1.7.0
1.7.1
1.7.2
1.7.3
1.8.0
1.8.1
1.8.2
1.8.2.post0
1.8.2.post1
1.9.0
1.9.1
1.9.1.post0
1.9.2
1.9.2.post0
Fixed in
1.16.0
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-47783
GHSA-8jhr-wpcm-hh4h
PYSEC-2025-124
May 15, 2025
label-studio vulnerable to Cross-Site Scripting (Reflected) via the label_config parameter.
High
Network
Low
None
SummaryThe vulnerability allows an attacker to inject a malicious script into the context of a web page, which can lead to data theft, unauthorized actions on behalf of the user, and other attacks. DetailsThe vulnerability is reproducible when sending a properly formatted request to the
The vulnerability is specifically located in line 57, where HttpResponse is used.
PoCSend the following request after changing the
Or you can create a vulnerable HTML page by changing
Impact
Affected versions
0.4.1
0.4.2
0.4.3
0.4.4
0.4.4.post1
0.4.4.post2
0.4.5
0.4.6
0.4.6.post1
0.4.6.post2
0.4.7
0.4.8
+ 78 more Show less
0.5.0
0.5.1
0.6.0
0.6.1
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.4.post0
0.7.4.post1
0.7.5.post1
0.7.5.post2
0.8.0
0.8.0.post0
0.8.1
0.8.1.post0
0.8.2
0.8.2.post0
0.9.0
0.9.0.post2
0.9.0.post3
0.9.0.post4
0.9.0.post5
0.9.1
0.9.1.post0
0.9.1.post1
0.9.1.post2
1.0.0
1.0.0.post0
1.0.0.post1
1.0.0.post2
1.0.0.post3
1.0.1
1.0.2
1.0.2.post0
1.1.0
1.1.0rc0
1.1.1
1.10.0
1.10.0.post0
1.10.1
1.11.0
1.12.0
1.12.0.post0
1.12.1
1.13.0
1.13.1
1.14.0
1.14.0.post0
1.15.0
1.16.0
1.17.0
1.2
1.3
1.3.post0
1.3.post1
1.4
1.4.1
1.4.1.post0
1.4.1.post1
1.5.0
1.5.0.post0
1.6.0
1.7.0
1.7.1
1.7.2
1.7.3
1.8.0
1.8.1
1.8.2
1.8.2.post0
1.8.2.post1
1.9.0
1.9.1
1.9.1.post0
1.9.2
1.9.2.post0
Fixed in
1.18.0
References
Updated Jun 06, 2026 · Source: OSV.dev
CVE-2024-26152
PYSEC-2024-249
GHSA-6xv9-957j-qfhg
Feb 22, 2024
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
SummaryOn all Label Studio versions prior to 1.11.0, data imported via file upload feature is not properly sanitized prior to being rendered within a DetailsNeed permission to use the "data import" function. This was reproduced on Label Studio 1.10.1. PoC
The following are the contents of the files used in the PoC
ImpactMalicious scripts can be injected into the code, and when linked with vulnerabilities such as CSRF, it can cause even greater damage. In particular, It can become a source of further attacks, especially when linked to social engineering. Affected versions
0.4.1
0.4.2
0.4.3
0.4.4
0.4.4.post1
0.4.4.post2
0.4.5
0.4.6
0.4.6.post1
0.4.6.post2
0.4.7
0.4.8
+ 113 more Show less
0.5.0
0.5.1
0.6.0
0.6.1
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.4.post0
0.7.4.post1
0.7.5.post1
0.7.5.post2
0.8.0
0.8.0.post0
0.8.1
0.8.1.post0
0.8.2
0.8.2.post0
0.9.0
0.9.0.post2
0.9.0.post3
0.9.0.post4
0.9.0.post5
0.9.1
0.9.1.post0
0.9.1.post1
0.9.1.post2
1.0.0
1.0.0.post0
1.0.0.post1
1.0.0.post2
1.0.0.post3
1.0.1
1.0.2
1.0.2.post0
1.1.0
1.1.0rc0
1.1.1
1.10.0
1.10.0.post0
1.10.1
1.2
1.3
1.3.post0
1.3.post1
1.4
1.4.1
1.4.1.post0
1.4.1.post1
1.5.0
1.5.0.post0
1.6.0
1.7.0
1.7.1
1.7.2
1.7.3
1.8.0
1.8.1
1.8.2
1.8.2.post0
1.8.2.post1
1.9.0
1.9.1
1.9.1.post0
1.9.2
1.9.2.post0
v1.4.1
v1.4.0
v1.3.0
v1.2.0
v1.1.1
v1.1.0
v1.0.2
v1.0.1
v1.0.0
v0.9.1.post1
v0.9.1.post0
v0.9.0.post5
v0.9.0.post4
v0.9.0.post3
v0.9.0
v0.8.2
v0.8.1
v0.8.0
v0.7.5.post0
v0.7.3
v0.7.2
v0.7.1
v0.7.0
v0.6.1
v0.6.0
v0.5.1
v0.4.8
v0.4.7
v0.4.6
v0.4.5
v0.4.4
v0.4.0
v0.3.0
v0.2.2
v.0.2.1-8
v.0.2.1-5
v.0.2.1-4
v.0.2.1-3
v.0.2.1-2
v.0.2.0
v.0.1.6
v.0.1.5
v.0.1.4
v.0.1.2
v.0.1.1
v.0.1.0
Fixed in
1.11.0
References
Updated Jun 10, 2026 · Source: OSV.dev
CVE-2023-47116
GHSA-p59w-9gqw-wj8r
PYSEC-2024-127
Jan 31, 2024
Label Studio SSRF on Import Bypassing `SSRF_PROTECTION_ENABLED` Protections
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
IntroductionThis write-up describes a vulnerability found in Label Studio, a popular open source data labeling tool. The vulnerability affects all versions of Label Studio prior to OverviewLabel Studio's SSRF protections that can be enabled by setting the DescriptionThe following
The
The issue here is the SSRF validation is only performed before the request is sent, and does not validate the destination IP address. Therefore, an attacker can either redirect the request or perform a DNS rebinding attack to bypass this protection. Proof of ConceptBoth the HTTP redirection and DNS rebinding methods for bypassing Label Studio's SSRF protections are explained below. HTTP RedirectionThe python
DNS Rebinding AttackDNS rebinding can bypass SSRF protections by resolving to an external IP address for the first resolution, but when the request is sent resolves to an internal IP address that is blocked. For an example, the domain ImpactSSRF vulnerabilities pose a significant risk on cloud environments, since instance credentials are managed by internal web APIs. An attacker can bypass Label Studio's SSRF protections to access internal web servers and partially compromise the confidentiality of those internal servers. Remediation Advice
Discovered
Affected versions
0.4.1
0.4.2
0.4.3
0.4.4
0.4.4.post1
0.4.4.post2
0.4.5
0.4.6
0.4.6.post1
0.4.6.post2
0.4.7
0.4.8
+ 67 more Show less
0.5.0
0.5.1
0.6.0
0.6.1
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.4.post0
0.7.4.post1
0.7.5.post1
0.7.5.post2
0.8.0
0.8.0.post0
0.8.1
0.8.1.post0
0.8.2
0.8.2.post0
0.9.0
0.9.0.post2
0.9.0.post3
0.9.0.post4
0.9.0.post5
0.9.1
0.9.1.post0
0.9.1.post1
0.9.1.post2
1.0.0
1.0.0.post0
1.0.0.post1
1.0.0.post2
1.0.0.post3
1.0.1
1.0.2
1.0.2.post0
1.1.0
1.1.0rc0
1.1.1
1.10.0
1.10.0.post0
1.10.1
1.2
1.3
1.3.post0
1.3.post1
1.4
1.4.1
1.4.1.post0
1.4.1.post1
1.5.0
1.5.0.post0
1.6.0
1.7.0
1.7.1
1.7.2
1.7.3
1.8.0
1.8.1
1.8.2
1.8.2.post0
1.8.2.post1
1.9.0
1.9.1
1.9.1.post0
1.9.2
1.9.2.post0
Fixed in
1.11.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-23633
GHSA-fq23-g58m-799r
PYSEC-2024-128
Jan 24, 2024
Cross-site Scripting Vulnerability on Data Import
4.7
/ 10
Medium
Network
Low
None
Required
Changed
Low
None
None
IntroductionThis write-up describes a vulnerability found in Label Studio, a popular open source data labeling tool. The vulnerability affects all versions of Label Studio prior to OverviewLabel Studio had a remote import feature allowed users to import data from a remote web source, that was downloaded and could be viewed on the website. This feature could had been abused to download a HTML file that executed malicious JavaScript code in the context of the Label Studio website. DescriptionThe following code snippet in Label Studio showed that is a URL passed the SSRF verification checks, the contents of the file would be downloaded using the filename in the URL.
The downloaded file path could then be retrieved by sending a request to
Since the Proof of ConceptBelow were the steps to recreate this issue:
ImpactExecuting arbitrary JavaScript could result in an attacker performing malicious actions on Label Studio users if they visit the crafted avatar image. For an example, an attacker can craft a JavaScript payload that adds a new Django Super Administrator user if a Django administrator visits the image. Remediation Advice
Discovered
Affected versions
0.4.1
0.4.2
0.4.3
0.4.4
0.4.4.post1
0.4.4.post2
0.4.5
0.4.6
0.4.6.post1
0.4.6.post2
0.4.7
0.4.8
+ 66 more Show less
0.5.0
0.5.1
0.6.0
0.6.1
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.4.post0
0.7.4.post1
0.7.5.post1
0.7.5.post2
0.8.0
0.8.0.post0
0.8.1
0.8.1.post0
0.8.2
0.8.2.post0
0.9.0
0.9.0.post2
0.9.0.post3
0.9.0.post4
0.9.0.post5
0.9.1
0.9.1.post0
0.9.1.post1
0.9.1.post2
1.0.0
1.0.0.post0
1.0.0.post1
1.0.0.post2
1.0.0.post3
1.0.1
1.0.2
1.0.2.post0
1.1.0
1.1.0rc0
1.1.1
1.10.0
1.10.0.post0
1.2
1.3
1.3.post0
1.3.post1
1.4
1.4.1
1.4.1.post0
1.4.1.post1
1.5.0
1.5.0.post0
1.6.0
1.7.0
1.7.1
1.7.2
1.7.3
1.8.0
1.8.1
1.8.2
1.8.2.post0
1.8.2.post1
1.9.0
1.9.1
1.9.1.post0
1.9.2
1.9.2.post0
Fixed in
1.10.1
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2023-47115
GHSA-q68h-xwq5-mm7x
PYSEC-2024-126
Jan 24, 2024
Cross-site Scripting Vulnerability on Avatar Upload
7.1
/ 10
High
Network
Low
None
Required
Changed
Low
Low
Low
IntroductionThis write-up describes a vulnerability found in Label Studio, a popular open source data labeling tool. The vulnerability affects all versions of Label Studio prior to OverviewLabel Studio has a cross-site scripting (XSS) vulnerability that could be exploited when an authenticated user uploads a crafted image file for their avatar that gets rendered as a HTML file on the website. DescriptionThe following code snippet in Label Studio shows that the only verification check is that the file is an image by extracting the dimensions from the file.
Label Studio serves avatar images using Django's built-in
The issue with the Django Proof of ConceptBelow are the steps to reproduce this issue and execute JavaScript code in the context of the Label Studio website.
ImpactExecuting arbitrary JavaScript could result in an attacker performing malicious actions on Label Studio users if they visit the crafted avatar image. For an example, an attacker can craft a JavaScript payload that adds a new Django Super Administrator user if a Django administrator visits the image. Remediation Advice
Discovered
Affected versions
0.4.1
0.4.2
0.4.3
0.4.4
0.4.4.post1
0.4.4.post2
0.4.5
0.4.6
0.4.6.post1
0.4.6.post2
0.4.7
0.4.8
+ 62 more Show less
0.5.0
0.5.1
0.6.0
0.6.1
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.4.post0
0.7.4.post1
0.7.5.post1
0.7.5.post2
0.8.0
0.8.0.post0
0.8.1
0.8.1.post0
0.8.2
0.8.2.post0
0.9.0
0.9.0.post2
0.9.0.post3
0.9.0.post4
0.9.0.post5
0.9.1
0.9.1.post0
0.9.1.post1
0.9.1.post2
1.0.0
1.0.0.post0
1.0.0.post1
1.0.0.post2
1.0.0.post3
1.0.1
1.0.2
1.0.2.post0
1.1.0
1.1.0rc0
1.1.1
1.2
1.3
1.3.post0
1.3.post1
1.4
1.4.1
1.4.1.post0
1.4.1.post1
1.5.0
1.5.0.post0
1.6.0
1.7.0
1.7.1
1.7.2
1.7.3
1.8.0
1.8.1
1.8.2
1.8.2.post0
1.8.2.post1
1.9.0
1.9.1
1.9.1.post0
Fixed in
1.9.2
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2023-47117
GHSA-6hjj-gq77-j4qw
PYSEC-2023-275
Nov 14, 2023
Label Studio Object Relational Mapper Leak Vulnerability in Filtering Task
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
IntroductionThis write-up describes a vulnerability found in Label Studio, a popular open source data labeling tool. The vulnerability affects all versions of Label Studio prior to OverviewIn all current versions of Label Studio, the application allows users to insecurely set filters for filtering tasks. An attacker can construct a filter chain to filter tasks based on sensitive fields for all user accounts on the platform by exploiting Django's Object Relational Mapper (ORM). Since the results of query can be manipulated by the ORM filter, an attacker can leak these sensitive fields character by character. For an example, the following filter chain will task results by the password hash of an account on Label Studio.
For consistency, this type of vulnerability will be termed as ORM Leak in the rest of this disclosure. In addition, Label Studio had a hard coded secret key that an attacker can use to forge a session token of any user by exploiting this ORM Leak vulnerability to leak account password hashes. DescriptionThe following code snippet from the
These
The
The following code snippet of the
Finally, the
Proof of ConceptBelow are the steps to exploit about how to exploit this vulnerability to leak the password hash of an account on Label Studio.
The following example GIF demonstrates exploiting this ORM Leak vulnerability to retrieve the password hash
ImpactThis vulnerability can be exploited to completely compromise the confidentiality of highly sensitive account information, such as account password hashes. For all versions Remediation Advice
Discovered
| ||
1.1.0rc0
pre
12 CVEs
CVE-2026-22033
PYSEC-2026-1502
GHSA-2mq9-hm29-8qch
Jul 07, 2026
Label Studio is vulnerable to full account takeover by chaining Stored XSS + IDOR in User Profile via custom_hotkeys field
Critical
Network
Low
Low
None
PrologueThese vulnerabilities have been found and chained by DCODX-AI. Validation of the exploit chain has been confirmed manually. SummaryA persistent stored cross-site scripting (XSS) vulnerability exists in the custom_hotkeys functionality of the application. An authenticated attacker (or one who can trick a user/administrator into updating their custom_hotkeys) can inject JavaScript code that executes in other users’ browsers when those users load any page using the DetailsWithin
Here, user.custom_hotkeys is run through json_dumps_ensure_ascii (in In
The serializer allows
When another user loads a page using templates/base.html (for example PoC
Example request
Example response
ImpactExploitation impact:
Who is impacted:
Affected versions
0.4.1
0.4.2
0.4.3
0.4.4
0.4.4.post1
0.4.4.post2
0.4.5
0.4.6
0.4.6.post1
0.4.6.post2
0.4.7
0.4.8
+ 83 more Show less
0.5.0
0.5.1
0.6.0
0.6.1
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.4.post0
0.7.4.post1
0.7.5.post1
0.7.5.post2
0.8.0
0.8.0.post0
0.8.1
0.8.1.post0
0.8.2
0.8.2.post0
0.9.0
0.9.0.post2
0.9.0.post3
0.9.0.post4
0.9.0.post5
0.9.1
0.9.1.post0
0.9.1.post1
0.9.1.post2
1.0.0
1.0.0.post0
1.0.0.post1
1.0.0.post2
1.0.0.post3
1.0.1
1.0.2
1.0.2.post0
1.1.0
1.1.0rc0
1.1.1
1.10.0
1.10.0.post0
1.10.1
1.11.0
1.12.0
1.12.0.post0
1.12.1
1.13.0
1.13.1
1.14.0
1.14.0.post0
1.15.0
1.16.0
1.17.0
1.18.0
1.19.0
1.2
1.20.0
1.21.0
1.22.0
1.3
1.3.post0
1.3.post1
1.4
1.4.1
1.4.1.post0
1.4.1.post1
1.5.0
1.5.0.post0
1.6.0
1.7.0
1.7.1
1.7.2
1.7.3
1.8.0
1.8.1
1.8.2
1.8.2.post0
1.8.2.post1
1.9.0
1.9.1
1.9.1.post0
1.9.2
1.9.2.post0
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-25297
PYSEC-2026-1503
GHSA-m238-fmcw-wh58
Jul 07, 2026
Label Studio allows Server-Side Request Forgery in the S3 Storage Endpoint
8.6
/ 10
High
Network
Low
None
None
Changed
High
None
None
DescriptionLabel Studio's S3 storage integration feature contains a Server-Side Request Forgery (SSRF) vulnerability in its endpoint configuration. When creating an S3 storage connection, the application allows users to specify a custom S3 endpoint URL via the s3_endpoint parameter. This endpoint URL is passed directly to the boto3 AWS SDK without proper validation or restrictions on the protocol or destination. The vulnerability allows an attacker to make the application send HTTP requests to arbitrary internal services by specifying them as the S3 endpoint. When the storage sync operation is triggered, the application attempts to make S3 API calls to the specified endpoint, effectively making HTTP requests to the target service and returning the response in error messages. This SSRF vulnerability enables attackers to bypass network segmentation and access internal services that should not be accessible from the external network. The vulnerability is particularly severe because error messages from failed requests contain the full response body, allowing data exfiltration from internal services. Steps to reproduce
The application will attempt to connect to the specified endpoint URL as if it were an S3 service. When the request fails due to invalid S3 API responses, the error message will contain the raw response from the internal service, allowing access to internal resources. Mitigations
ImpactThis vulnerability has high severity as it allows authenticated users to make requests to arbitrary internal services from the application server, potentially exposing sensitive internal resources and bypassing network segmentation. The inclusion of response data in error messages makes this particularly effective for data exfiltration. Affected versions
0.4.1
0.4.2
0.4.3
0.4.4
0.4.4.post1
0.4.4.post2
0.4.5
0.4.6
0.4.6.post1
0.4.6.post2
0.4.7
0.4.8
+ 76 more Show less
0.5.0
0.5.1
0.6.0
0.6.1
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.4.post0
0.7.4.post1
0.7.5.post1
0.7.5.post2
0.8.0
0.8.0.post0
0.8.1
0.8.1.post0
0.8.2
0.8.2.post0
0.9.0
0.9.0.post2
0.9.0.post3
0.9.0.post4
0.9.0.post5
0.9.1
0.9.1.post0
0.9.1.post1
0.9.1.post2
1.0.0
1.0.0.post0
1.0.0.post1
1.0.0.post2
1.0.0.post3
1.0.1
1.0.2
1.0.2.post0
1.1.0
1.1.0rc0
1.1.1
1.10.0
1.10.0.post0
1.10.1
1.11.0
1.12.0
1.12.0.post0
1.12.1
1.13.0
1.13.1
1.14.0
1.14.0.post0
1.15.0
1.2
1.3
1.3.post0
1.3.post1
1.4
1.4.1
1.4.1.post0
1.4.1.post1
1.5.0
1.5.0.post0
1.6.0
1.7.0
1.7.1
1.7.2
1.7.3
1.8.0
1.8.1
1.8.2
1.8.2.post0
1.8.2.post1
1.9.0
1.9.1
1.9.1.post0
1.9.2
1.9.2.post0
Fixed in
1.16.0
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-25296
PYSEC-2026-1504
GHSA-wpq5-3366-mqw4
Jul 07, 2026
Label Studio allows Cross-Site Scripting (XSS) via GET request to `/projects/upload-example` endpoint
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
DescriptionLabel Studio's The vulnerability exists because the upload-example endpoint renders user-provided HTML content without proper sanitization on a GET request. This allows attackers to inject and execute arbitrary JavaScript in victims' browsers by getting them to visit a maliciously crafted URL. This is considered vulnerable because it enables attackers to execute JavaScript in victims' contexts, potentially allowing theft of sensitive data, session hijacking, or other malicious actions. Steps to reproduce
When executed, the payload causes the application to render an HTML page containing an img tag that fails to load, triggering the onerror event handler which executes base64-decoded JavaScript, demonstrating successful XSS execution in the victim's browser. Mitigations
ImpactThe vulnerability requires no special privileges and can be exploited by getting a victim to visit a crafted URL. The impact is high as it allows arbitrary JavaScript execution in victims' browsers, potentially exposing sensitive data or enabling account takeover through session theft. Affected versions
0.4.1
0.4.2
0.4.3
0.4.4
0.4.4.post1
0.4.4.post2
0.4.5
0.4.6
0.4.6.post1
0.4.6.post2
0.4.7
0.4.8
+ 76 more Show less
0.5.0
0.5.1
0.6.0
0.6.1
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.4.post0
0.7.4.post1
0.7.5.post1
0.7.5.post2
0.8.0
0.8.0.post0
0.8.1
0.8.1.post0
0.8.2
0.8.2.post0
0.9.0
0.9.0.post2
0.9.0.post3
0.9.0.post4
0.9.0.post5
0.9.1
0.9.1.post0
0.9.1.post1
0.9.1.post2
1.0.0
1.0.0.post0
1.0.0.post1
1.0.0.post2
1.0.0.post3
1.0.1
1.0.2
1.0.2.post0
1.1.0
1.1.0rc0
1.1.1
1.10.0
1.10.0.post0
1.10.1
1.11.0
1.12.0
1.12.0.post0
1.12.1
1.13.0
1.13.1
1.14.0
1.14.0.post0
1.15.0
1.2
1.3
1.3.post0
1.3.post1
1.4
1.4.1
1.4.1.post0
1.4.1.post1
1.5.0
1.5.0.post0
1.6.0
1.7.0
1.7.1
1.7.2
1.7.3
1.8.0
1.8.1
1.8.2
1.8.2.post0
1.8.2.post1
1.9.0
1.9.1
1.9.1.post0
1.9.2
1.9.2.post0
Fixed in
1.16.0
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-47783
GHSA-8jhr-wpcm-hh4h
PYSEC-2025-124
May 15, 2025
label-studio vulnerable to Cross-Site Scripting (Reflected) via the label_config parameter.
High
Network
Low
None
SummaryThe vulnerability allows an attacker to inject a malicious script into the context of a web page, which can lead to data theft, unauthorized actions on behalf of the user, and other attacks. DetailsThe vulnerability is reproducible when sending a properly formatted request to the
The vulnerability is specifically located in line 57, where HttpResponse is used.
PoCSend the following request after changing the
Or you can create a vulnerable HTML page by changing
Impact
Affected versions
0.4.1
0.4.2
0.4.3
0.4.4
0.4.4.post1
0.4.4.post2
0.4.5
0.4.6
0.4.6.post1
0.4.6.post2
0.4.7
0.4.8
+ 78 more Show less
0.5.0
0.5.1
0.6.0
0.6.1
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.4.post0
0.7.4.post1
0.7.5.post1
0.7.5.post2
0.8.0
0.8.0.post0
0.8.1
0.8.1.post0
0.8.2
0.8.2.post0
0.9.0
0.9.0.post2
0.9.0.post3
0.9.0.post4
0.9.0.post5
0.9.1
0.9.1.post0
0.9.1.post1
0.9.1.post2
1.0.0
1.0.0.post0
1.0.0.post1
1.0.0.post2
1.0.0.post3
1.0.1
1.0.2
1.0.2.post0
1.1.0
1.1.0rc0
1.1.1
1.10.0
1.10.0.post0
1.10.1
1.11.0
1.12.0
1.12.0.post0
1.12.1
1.13.0
1.13.1
1.14.0
1.14.0.post0
1.15.0
1.16.0
1.17.0
1.2
1.3
1.3.post0
1.3.post1
1.4
1.4.1
1.4.1.post0
1.4.1.post1
1.5.0
1.5.0.post0
1.6.0
1.7.0
1.7.1
1.7.2
1.7.3
1.8.0
1.8.1
1.8.2
1.8.2.post0
1.8.2.post1
1.9.0
1.9.1
1.9.1.post0
1.9.2
1.9.2.post0
Fixed in
1.18.0
References
Updated Jun 06, 2026 · Source: OSV.dev
CVE-2024-26152
PYSEC-2024-249
GHSA-6xv9-957j-qfhg
Feb 22, 2024
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
SummaryOn all Label Studio versions prior to 1.11.0, data imported via file upload feature is not properly sanitized prior to being rendered within a DetailsNeed permission to use the "data import" function. This was reproduced on Label Studio 1.10.1. PoC
The following are the contents of the files used in the PoC
ImpactMalicious scripts can be injected into the code, and when linked with vulnerabilities such as CSRF, it can cause even greater damage. In particular, It can become a source of further attacks, especially when linked to social engineering. Affected versions
0.4.1
0.4.2
0.4.3
0.4.4
0.4.4.post1
0.4.4.post2
0.4.5
0.4.6
0.4.6.post1
0.4.6.post2
0.4.7
0.4.8
+ 113 more Show less
0.5.0
0.5.1
0.6.0
0.6.1
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.4.post0
0.7.4.post1
0.7.5.post1
0.7.5.post2
0.8.0
0.8.0.post0
0.8.1
0.8.1.post0
0.8.2
0.8.2.post0
0.9.0
0.9.0.post2
0.9.0.post3
0.9.0.post4
0.9.0.post5
0.9.1
0.9.1.post0
0.9.1.post1
0.9.1.post2
1.0.0
1.0.0.post0
1.0.0.post1
1.0.0.post2
1.0.0.post3
1.0.1
1.0.2
1.0.2.post0
1.1.0
1.1.0rc0
1.1.1
1.10.0
1.10.0.post0
1.10.1
1.2
1.3
1.3.post0
1.3.post1
1.4
1.4.1
1.4.1.post0
1.4.1.post1
1.5.0
1.5.0.post0
1.6.0
1.7.0
1.7.1
1.7.2
1.7.3
1.8.0
1.8.1
1.8.2
1.8.2.post0
1.8.2.post1
1.9.0
1.9.1
1.9.1.post0
1.9.2
1.9.2.post0
v1.4.1
v1.4.0
v1.3.0
v1.2.0
v1.1.1
v1.1.0
v1.0.2
v1.0.1
v1.0.0
v0.9.1.post1
v0.9.1.post0
v0.9.0.post5
v0.9.0.post4
v0.9.0.post3
v0.9.0
v0.8.2
v0.8.1
v0.8.0
v0.7.5.post0
v0.7.3
v0.7.2
v0.7.1
v0.7.0
v0.6.1
v0.6.0
v0.5.1
v0.4.8
v0.4.7
v0.4.6
v0.4.5
v0.4.4
v0.4.0
v0.3.0
v0.2.2
v.0.2.1-8
v.0.2.1-5
v.0.2.1-4
v.0.2.1-3
v.0.2.1-2
v.0.2.0
v.0.1.6
v.0.1.5
v.0.1.4
v.0.1.2
v.0.1.1
v.0.1.0
Fixed in
1.11.0
References
Updated Jun 10, 2026 · Source: OSV.dev
CVE-2023-47116
GHSA-p59w-9gqw-wj8r
PYSEC-2024-127
Jan 31, 2024
Label Studio SSRF on Import Bypassing `SSRF_PROTECTION_ENABLED` Protections
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
IntroductionThis write-up describes a vulnerability found in Label Studio, a popular open source data labeling tool. The vulnerability affects all versions of Label Studio prior to OverviewLabel Studio's SSRF protections that can be enabled by setting the DescriptionThe following
The
The issue here is the SSRF validation is only performed before the request is sent, and does not validate the destination IP address. Therefore, an attacker can either redirect the request or perform a DNS rebinding attack to bypass this protection. Proof of ConceptBoth the HTTP redirection and DNS rebinding methods for bypassing Label Studio's SSRF protections are explained below. HTTP RedirectionThe python
DNS Rebinding AttackDNS rebinding can bypass SSRF protections by resolving to an external IP address for the first resolution, but when the request is sent resolves to an internal IP address that is blocked. For an example, the domain ImpactSSRF vulnerabilities pose a significant risk on cloud environments, since instance credentials are managed by internal web APIs. An attacker can bypass Label Studio's SSRF protections to access internal web servers and partially compromise the confidentiality of those internal servers. Remediation Advice
Discovered
Affected versions
0.4.1
0.4.2
0.4.3
0.4.4
0.4.4.post1
0.4.4.post2
0.4.5
0.4.6
0.4.6.post1
0.4.6.post2
0.4.7
0.4.8
+ 67 more Show less
0.5.0
0.5.1
0.6.0
0.6.1
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.4.post0
0.7.4.post1
0.7.5.post1
0.7.5.post2
0.8.0
0.8.0.post0
0.8.1
0.8.1.post0
0.8.2
0.8.2.post0
0.9.0
0.9.0.post2
0.9.0.post3
0.9.0.post4
0.9.0.post5
0.9.1
0.9.1.post0
0.9.1.post1
0.9.1.post2
1.0.0
1.0.0.post0
1.0.0.post1
1.0.0.post2
1.0.0.post3
1.0.1
1.0.2
1.0.2.post0
1.1.0
1.1.0rc0
1.1.1
1.10.0
1.10.0.post0
1.10.1
1.2
1.3
1.3.post0
1.3.post1
1.4
1.4.1
1.4.1.post0
1.4.1.post1
1.5.0
1.5.0.post0
1.6.0
1.7.0
1.7.1
1.7.2
1.7.3
1.8.0
1.8.1
1.8.2
1.8.2.post0
1.8.2.post1
1.9.0
1.9.1
1.9.1.post0
1.9.2
1.9.2.post0
Fixed in
1.11.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-23633
GHSA-fq23-g58m-799r
PYSEC-2024-128
Jan 24, 2024
Cross-site Scripting Vulnerability on Data Import
4.7
/ 10
Medium
Network
Low
None
Required
Changed
Low
None
None
IntroductionThis write-up describes a vulnerability found in Label Studio, a popular open source data labeling tool. The vulnerability affects all versions of Label Studio prior to OverviewLabel Studio had a remote import feature allowed users to import data from a remote web source, that was downloaded and could be viewed on the website. This feature could had been abused to download a HTML file that executed malicious JavaScript code in the context of the Label Studio website. DescriptionThe following code snippet in Label Studio showed that is a URL passed the SSRF verification checks, the contents of the file would be downloaded using the filename in the URL.
The downloaded file path could then be retrieved by sending a request to
Since the Proof of ConceptBelow were the steps to recreate this issue:
ImpactExecuting arbitrary JavaScript could result in an attacker performing malicious actions on Label Studio users if they visit the crafted avatar image. For an example, an attacker can craft a JavaScript payload that adds a new Django Super Administrator user if a Django administrator visits the image. Remediation Advice
Discovered
Affected versions
0.4.1
0.4.2
0.4.3
0.4.4
0.4.4.post1
0.4.4.post2
0.4.5
0.4.6
0.4.6.post1
0.4.6.post2
0.4.7
0.4.8
+ 66 more Show less
0.5.0
0.5.1
0.6.0
0.6.1
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.4.post0
0.7.4.post1
0.7.5.post1
0.7.5.post2
0.8.0
0.8.0.post0
0.8.1
0.8.1.post0
0.8.2
0.8.2.post0
0.9.0
0.9.0.post2
0.9.0.post3
0.9.0.post4
0.9.0.post5
0.9.1
0.9.1.post0
0.9.1.post1
0.9.1.post2
1.0.0
1.0.0.post0
1.0.0.post1
1.0.0.post2
1.0.0.post3
1.0.1
1.0.2
1.0.2.post0
1.1.0
1.1.0rc0
1.1.1
1.10.0
1.10.0.post0
1.2
1.3
1.3.post0
1.3.post1
1.4
1.4.1
1.4.1.post0
1.4.1.post1
1.5.0
1.5.0.post0
1.6.0
1.7.0
1.7.1
1.7.2
1.7.3
1.8.0
1.8.1
1.8.2
1.8.2.post0
1.8.2.post1
1.9.0
1.9.1
1.9.1.post0
1.9.2
1.9.2.post0
Fixed in
1.10.1
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2023-47115
GHSA-q68h-xwq5-mm7x
PYSEC-2024-126
Jan 24, 2024
Cross-site Scripting Vulnerability on Avatar Upload
7.1
/ 10
High
Network
Low
None
Required
Changed
Low
Low
Low
IntroductionThis write-up describes a vulnerability found in Label Studio, a popular open source data labeling tool. The vulnerability affects all versions of Label Studio prior to OverviewLabel Studio has a cross-site scripting (XSS) vulnerability that could be exploited when an authenticated user uploads a crafted image file for their avatar that gets rendered as a HTML file on the website. DescriptionThe following code snippet in Label Studio shows that the only verification check is that the file is an image by extracting the dimensions from the file.
Label Studio serves avatar images using Django's built-in
The issue with the Django Proof of ConceptBelow are the steps to reproduce this issue and execute JavaScript code in the context of the Label Studio website.
ImpactExecuting arbitrary JavaScript could result in an attacker performing malicious actions on Label Studio users if they visit the crafted avatar image. For an example, an attacker can craft a JavaScript payload that adds a new Django Super Administrator user if a Django administrator visits the image. Remediation Advice
Discovered
Affected versions
0.4.1
0.4.2
0.4.3
0.4.4
0.4.4.post1
0.4.4.post2
0.4.5
0.4.6
0.4.6.post1
0.4.6.post2
0.4.7
0.4.8
+ 62 more Show less
0.5.0
0.5.1
0.6.0
0.6.1
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.4.post0
0.7.4.post1
0.7.5.post1
0.7.5.post2
0.8.0
0.8.0.post0
0.8.1
0.8.1.post0
0.8.2
0.8.2.post0
0.9.0
0.9.0.post2
0.9.0.post3
0.9.0.post4
0.9.0.post5
0.9.1
0.9.1.post0
0.9.1.post1
0.9.1.post2
1.0.0
1.0.0.post0
1.0.0.post1
1.0.0.post2
1.0.0.post3
1.0.1
1.0.2
1.0.2.post0
1.1.0
1.1.0rc0
1.1.1
1.2
1.3
1.3.post0
1.3.post1
1.4
1.4.1
1.4.1.post0
1.4.1.post1
1.5.0
1.5.0.post0
1.6.0
1.7.0
1.7.1
1.7.2
1.7.3
1.8.0
1.8.1
1.8.2
1.8.2.post0
1.8.2.post1
1.9.0
1.9.1
1.9.1.post0
Fixed in
1.9.2
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2023-47117
GHSA-6hjj-gq77-j4qw
PYSEC-2023-275
Nov 14, 2023
Label Studio Object Relational Mapper Leak Vulnerability in Filtering Task
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
IntroductionThis write-up describes a vulnerability found in Label Studio, a popular open source data labeling tool. The vulnerability affects all versions of Label Studio prior to OverviewIn all current versions of Label Studio, the application allows users to insecurely set filters for filtering tasks. An attacker can construct a filter chain to filter tasks based on sensitive fields for all user accounts on the platform by exploiting Django's Object Relational Mapper (ORM). Since the results of query can be manipulated by the ORM filter, an attacker can leak these sensitive fields character by character. For an example, the following filter chain will task results by the password hash of an account on Label Studio.
For consistency, this type of vulnerability will be termed as ORM Leak in the rest of this disclosure. In addition, Label Studio had a hard coded secret key that an attacker can use to forge a session token of any user by exploiting this ORM Leak vulnerability to leak account password hashes. DescriptionThe following code snippet from the
These
The
The following code snippet of the
Finally, the
Proof of ConceptBelow are the steps to exploit about how to exploit this vulnerability to leak the password hash of an account on Label Studio.
The following example GIF demonstrates exploiting this ORM Leak vulnerability to retrieve the password hash
ImpactThis vulnerability can be exploited to completely compromise the confidentiality of highly sensitive account information, such as account password hashes. For all versions Remediation Advice
Discovered
| ||
1.0.2.post0
pre
12 CVEs
CVE-2026-22033
PYSEC-2026-1502
GHSA-2mq9-hm29-8qch
Jul 07, 2026
Label Studio is vulnerable to full account takeover by chaining Stored XSS + IDOR in User Profile via custom_hotkeys field
Critical
Network
Low
Low
None
PrologueThese vulnerabilities have been found and chained by DCODX-AI. Validation of the exploit chain has been confirmed manually. SummaryA persistent stored cross-site scripting (XSS) vulnerability exists in the custom_hotkeys functionality of the application. An authenticated attacker (or one who can trick a user/administrator into updating their custom_hotkeys) can inject JavaScript code that executes in other users’ browsers when those users load any page using the DetailsWithin
Here, user.custom_hotkeys is run through json_dumps_ensure_ascii (in In
The serializer allows
When another user loads a page using templates/base.html (for example PoC
Example request
Example response
ImpactExploitation impact:
Who is impacted:
Affected versions
0.4.1
0.4.2
0.4.3
0.4.4
0.4.4.post1
0.4.4.post2
0.4.5
0.4.6
0.4.6.post1
0.4.6.post2
0.4.7
0.4.8
+ 83 more Show less
0.5.0
0.5.1
0.6.0
0.6.1
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.4.post0
0.7.4.post1
0.7.5.post1
0.7.5.post2
0.8.0
0.8.0.post0
0.8.1
0.8.1.post0
0.8.2
0.8.2.post0
0.9.0
0.9.0.post2
0.9.0.post3
0.9.0.post4
0.9.0.post5
0.9.1
0.9.1.post0
0.9.1.post1
0.9.1.post2
1.0.0
1.0.0.post0
1.0.0.post1
1.0.0.post2
1.0.0.post3
1.0.1
1.0.2
1.0.2.post0
1.1.0
1.1.0rc0
1.1.1
1.10.0
1.10.0.post0
1.10.1
1.11.0
1.12.0
1.12.0.post0
1.12.1
1.13.0
1.13.1
1.14.0
1.14.0.post0
1.15.0
1.16.0
1.17.0
1.18.0
1.19.0
1.2
1.20.0
1.21.0
1.22.0
1.3
1.3.post0
1.3.post1
1.4
1.4.1
1.4.1.post0
1.4.1.post1
1.5.0
1.5.0.post0
1.6.0
1.7.0
1.7.1
1.7.2
1.7.3
1.8.0
1.8.1
1.8.2
1.8.2.post0
1.8.2.post1
1.9.0
1.9.1
1.9.1.post0
1.9.2
1.9.2.post0
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-25297
PYSEC-2026-1503
GHSA-m238-fmcw-wh58
Jul 07, 2026
Label Studio allows Server-Side Request Forgery in the S3 Storage Endpoint
8.6
/ 10
High
Network
Low
None
None
Changed
High
None
None
DescriptionLabel Studio's S3 storage integration feature contains a Server-Side Request Forgery (SSRF) vulnerability in its endpoint configuration. When creating an S3 storage connection, the application allows users to specify a custom S3 endpoint URL via the s3_endpoint parameter. This endpoint URL is passed directly to the boto3 AWS SDK without proper validation or restrictions on the protocol or destination. The vulnerability allows an attacker to make the application send HTTP requests to arbitrary internal services by specifying them as the S3 endpoint. When the storage sync operation is triggered, the application attempts to make S3 API calls to the specified endpoint, effectively making HTTP requests to the target service and returning the response in error messages. This SSRF vulnerability enables attackers to bypass network segmentation and access internal services that should not be accessible from the external network. The vulnerability is particularly severe because error messages from failed requests contain the full response body, allowing data exfiltration from internal services. Steps to reproduce
The application will attempt to connect to the specified endpoint URL as if it were an S3 service. When the request fails due to invalid S3 API responses, the error message will contain the raw response from the internal service, allowing access to internal resources. Mitigations
ImpactThis vulnerability has high severity as it allows authenticated users to make requests to arbitrary internal services from the application server, potentially exposing sensitive internal resources and bypassing network segmentation. The inclusion of response data in error messages makes this particularly effective for data exfiltration. Affected versions
0.4.1
0.4.2
0.4.3
0.4.4
0.4.4.post1
0.4.4.post2
0.4.5
0.4.6
0.4.6.post1
0.4.6.post2
0.4.7
0.4.8
+ 76 more Show less
0.5.0
0.5.1
0.6.0
0.6.1
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.4.post0
0.7.4.post1
0.7.5.post1
0.7.5.post2
0.8.0
0.8.0.post0
0.8.1
0.8.1.post0
0.8.2
0.8.2.post0
0.9.0
0.9.0.post2
0.9.0.post3
0.9.0.post4
0.9.0.post5
0.9.1
0.9.1.post0
0.9.1.post1
0.9.1.post2
1.0.0
1.0.0.post0
1.0.0.post1
1.0.0.post2
1.0.0.post3
1.0.1
1.0.2
1.0.2.post0
1.1.0
1.1.0rc0
1.1.1
1.10.0
1.10.0.post0
1.10.1
1.11.0
1.12.0
1.12.0.post0
1.12.1
1.13.0
1.13.1
1.14.0
1.14.0.post0
1.15.0
1.2
1.3
1.3.post0
1.3.post1
1.4
1.4.1
1.4.1.post0
1.4.1.post1
1.5.0
1.5.0.post0
1.6.0
1.7.0
1.7.1
1.7.2
1.7.3
1.8.0
1.8.1
1.8.2
1.8.2.post0
1.8.2.post1
1.9.0
1.9.1
1.9.1.post0
1.9.2
1.9.2.post0
Fixed in
1.16.0
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-25296
PYSEC-2026-1504
GHSA-wpq5-3366-mqw4
Jul 07, 2026
Label Studio allows Cross-Site Scripting (XSS) via GET request to `/projects/upload-example` endpoint
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
DescriptionLabel Studio's The vulnerability exists because the upload-example endpoint renders user-provided HTML content without proper sanitization on a GET request. This allows attackers to inject and execute arbitrary JavaScript in victims' browsers by getting them to visit a maliciously crafted URL. This is considered vulnerable because it enables attackers to execute JavaScript in victims' contexts, potentially allowing theft of sensitive data, session hijacking, or other malicious actions. Steps to reproduce
When executed, the payload causes the application to render an HTML page containing an img tag that fails to load, triggering the onerror event handler which executes base64-decoded JavaScript, demonstrating successful XSS execution in the victim's browser. Mitigations
ImpactThe vulnerability requires no special privileges and can be exploited by getting a victim to visit a crafted URL. The impact is high as it allows arbitrary JavaScript execution in victims' browsers, potentially exposing sensitive data or enabling account takeover through session theft. Affected versions
0.4.1
0.4.2
0.4.3
0.4.4
0.4.4.post1
0.4.4.post2
0.4.5
0.4.6
0.4.6.post1
0.4.6.post2
0.4.7
0.4.8
+ 76 more Show less
0.5.0
0.5.1
0.6.0
0.6.1
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.4.post0
0.7.4.post1
0.7.5.post1
0.7.5.post2
0.8.0
0.8.0.post0
0.8.1
0.8.1.post0
0.8.2
0.8.2.post0
0.9.0
0.9.0.post2
0.9.0.post3
0.9.0.post4
0.9.0.post5
0.9.1
0.9.1.post0
0.9.1.post1
0.9.1.post2
1.0.0
1.0.0.post0
1.0.0.post1
1.0.0.post2
1.0.0.post3
1.0.1
1.0.2
1.0.2.post0
1.1.0
1.1.0rc0
1.1.1
1.10.0
1.10.0.post0
1.10.1
1.11.0
1.12.0
1.12.0.post0
1.12.1
1.13.0
1.13.1
1.14.0
1.14.0.post0
1.15.0
1.2
1.3
1.3.post0
1.3.post1
1.4
1.4.1
1.4.1.post0
1.4.1.post1
1.5.0
1.5.0.post0
1.6.0
1.7.0
1.7.1
1.7.2
1.7.3
1.8.0
1.8.1
1.8.2
1.8.2.post0
1.8.2.post1
1.9.0
1.9.1
1.9.1.post0
1.9.2
1.9.2.post0
Fixed in
1.16.0
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-47783
GHSA-8jhr-wpcm-hh4h
PYSEC-2025-124
May 15, 2025
label-studio vulnerable to Cross-Site Scripting (Reflected) via the label_config parameter.
High
Network
Low
None
SummaryThe vulnerability allows an attacker to inject a malicious script into the context of a web page, which can lead to data theft, unauthorized actions on behalf of the user, and other attacks. DetailsThe vulnerability is reproducible when sending a properly formatted request to the
The vulnerability is specifically located in line 57, where HttpResponse is used.
PoCSend the following request after changing the
Or you can create a vulnerable HTML page by changing
Impact
Affected versions
0.4.1
0.4.2
0.4.3
0.4.4
0.4.4.post1
0.4.4.post2
0.4.5
0.4.6
0.4.6.post1
0.4.6.post2
0.4.7
0.4.8
+ 78 more Show less
0.5.0
0.5.1
0.6.0
0.6.1
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.4.post0
0.7.4.post1
0.7.5.post1
0.7.5.post2
0.8.0
0.8.0.post0
0.8.1
0.8.1.post0
0.8.2
0.8.2.post0
0.9.0
0.9.0.post2
0.9.0.post3
0.9.0.post4
0.9.0.post5
0.9.1
0.9.1.post0
0.9.1.post1
0.9.1.post2
1.0.0
1.0.0.post0
1.0.0.post1
1.0.0.post2
1.0.0.post3
1.0.1
1.0.2
1.0.2.post0
1.1.0
1.1.0rc0
1.1.1
1.10.0
1.10.0.post0
1.10.1
1.11.0
1.12.0
1.12.0.post0
1.12.1
1.13.0
1.13.1
1.14.0
1.14.0.post0
1.15.0
1.16.0
1.17.0
1.2
1.3
1.3.post0
1.3.post1
1.4
1.4.1
1.4.1.post0
1.4.1.post1
1.5.0
1.5.0.post0
1.6.0
1.7.0
1.7.1
1.7.2
1.7.3
1.8.0
1.8.1
1.8.2
1.8.2.post0
1.8.2.post1
1.9.0
1.9.1
1.9.1.post0
1.9.2
1.9.2.post0
Fixed in
1.18.0
References
Updated Jun 06, 2026 · Source: OSV.dev
CVE-2024-26152
PYSEC-2024-249
GHSA-6xv9-957j-qfhg
Feb 22, 2024
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
SummaryOn all Label Studio versions prior to 1.11.0, data imported via file upload feature is not properly sanitized prior to being rendered within a DetailsNeed permission to use the "data import" function. This was reproduced on Label Studio 1.10.1. PoC
The following are the contents of the files used in the PoC
ImpactMalicious scripts can be injected into the code, and when linked with vulnerabilities such as CSRF, it can cause even greater damage. In particular, It can become a source of further attacks, especially when linked to social engineering. Affected versions
0.4.1
0.4.2
0.4.3
0.4.4
0.4.4.post1
0.4.4.post2
0.4.5
0.4.6
0.4.6.post1
0.4.6.post2
0.4.7
0.4.8
+ 113 more Show less
0.5.0
0.5.1
0.6.0
0.6.1
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.4.post0
0.7.4.post1
0.7.5.post1
0.7.5.post2
0.8.0
0.8.0.post0
0.8.1
0.8.1.post0
0.8.2
0.8.2.post0
0.9.0
0.9.0.post2
0.9.0.post3
0.9.0.post4
0.9.0.post5
0.9.1
0.9.1.post0
0.9.1.post1
0.9.1.post2
1.0.0
1.0.0.post0
1.0.0.post1
1.0.0.post2
1.0.0.post3
1.0.1
1.0.2
1.0.2.post0
1.1.0
1.1.0rc0
1.1.1
1.10.0
1.10.0.post0
1.10.1
1.2
1.3
1.3.post0
1.3.post1
1.4
1.4.1
1.4.1.post0
1.4.1.post1
1.5.0
1.5.0.post0
1.6.0
1.7.0
1.7.1
1.7.2
1.7.3
1.8.0
1.8.1
1.8.2
1.8.2.post0
1.8.2.post1
1.9.0
1.9.1
1.9.1.post0
1.9.2
1.9.2.post0
v1.4.1
v1.4.0
v1.3.0
v1.2.0
v1.1.1
v1.1.0
v1.0.2
v1.0.1
v1.0.0
v0.9.1.post1
v0.9.1.post0
v0.9.0.post5
v0.9.0.post4
v0.9.0.post3
v0.9.0
v0.8.2
v0.8.1
v0.8.0
v0.7.5.post0
v0.7.3
v0.7.2
v0.7.1
v0.7.0
v0.6.1
v0.6.0
v0.5.1
v0.4.8
v0.4.7
v0.4.6
v0.4.5
v0.4.4
v0.4.0
v0.3.0
v0.2.2
v.0.2.1-8
v.0.2.1-5
v.0.2.1-4
v.0.2.1-3
v.0.2.1-2
v.0.2.0
v.0.1.6
v.0.1.5
v.0.1.4
v.0.1.2
v.0.1.1
v.0.1.0
Fixed in
1.11.0
References
Updated Jun 10, 2026 · Source: OSV.dev
CVE-2023-47116
GHSA-p59w-9gqw-wj8r
PYSEC-2024-127
Jan 31, 2024
Label Studio SSRF on Import Bypassing `SSRF_PROTECTION_ENABLED` Protections
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
IntroductionThis write-up describes a vulnerability found in Label Studio, a popular open source data labeling tool. The vulnerability affects all versions of Label Studio prior to OverviewLabel Studio's SSRF protections that can be enabled by setting the DescriptionThe following
The
The issue here is the SSRF validation is only performed before the request is sent, and does not validate the destination IP address. Therefore, an attacker can either redirect the request or perform a DNS rebinding attack to bypass this protection. Proof of ConceptBoth the HTTP redirection and DNS rebinding methods for bypassing Label Studio's SSRF protections are explained below. HTTP RedirectionThe python
DNS Rebinding AttackDNS rebinding can bypass SSRF protections by resolving to an external IP address for the first resolution, but when the request is sent resolves to an internal IP address that is blocked. For an example, the domain ImpactSSRF vulnerabilities pose a significant risk on cloud environments, since instance credentials are managed by internal web APIs. An attacker can bypass Label Studio's SSRF protections to access internal web servers and partially compromise the confidentiality of those internal servers. Remediation Advice
Discovered
Affected versions
0.4.1
0.4.2
0.4.3
0.4.4
0.4.4.post1
0.4.4.post2
0.4.5
0.4.6
0.4.6.post1
0.4.6.post2
0.4.7
0.4.8
+ 67 more Show less
0.5.0
0.5.1
0.6.0
0.6.1
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.4.post0
0.7.4.post1
0.7.5.post1
0.7.5.post2
0.8.0
0.8.0.post0
0.8.1
0.8.1.post0
0.8.2
0.8.2.post0
0.9.0
0.9.0.post2
0.9.0.post3
0.9.0.post4
0.9.0.post5
0.9.1
0.9.1.post0
0.9.1.post1
0.9.1.post2
1.0.0
1.0.0.post0
1.0.0.post1
1.0.0.post2
1.0.0.post3
1.0.1
1.0.2
1.0.2.post0
1.1.0
1.1.0rc0
1.1.1
1.10.0
1.10.0.post0
1.10.1
1.2
1.3
1.3.post0
1.3.post1
1.4
1.4.1
1.4.1.post0
1.4.1.post1
1.5.0
1.5.0.post0
1.6.0
1.7.0
1.7.1
1.7.2
1.7.3
1.8.0
1.8.1
1.8.2
1.8.2.post0
1.8.2.post1
1.9.0
1.9.1
1.9.1.post0
1.9.2
1.9.2.post0
Fixed in
1.11.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-23633
GHSA-fq23-g58m-799r
PYSEC-2024-128
Jan 24, 2024
Cross-site Scripting Vulnerability on Data Import
4.7
/ 10
Medium
Network
Low
None
Required
Changed
Low
None
None
IntroductionThis write-up describes a vulnerability found in Label Studio, a popular open source data labeling tool. The vulnerability affects all versions of Label Studio prior to OverviewLabel Studio had a remote import feature allowed users to import data from a remote web source, that was downloaded and could be viewed on the website. This feature could had been abused to download a HTML file that executed malicious JavaScript code in the context of the Label Studio website. DescriptionThe following code snippet in Label Studio showed that is a URL passed the SSRF verification checks, the contents of the file would be downloaded using the filename in the URL.
The downloaded file path could then be retrieved by sending a request to
Since the Proof of ConceptBelow were the steps to recreate this issue:
ImpactExecuting arbitrary JavaScript could result in an attacker performing malicious actions on Label Studio users if they visit the crafted avatar image. For an example, an attacker can craft a JavaScript payload that adds a new Django Super Administrator user if a Django administrator visits the image. Remediation Advice
Discovered
Affected versions
0.4.1
0.4.2
0.4.3
0.4.4
0.4.4.post1
0.4.4.post2
0.4.5
0.4.6
0.4.6.post1
0.4.6.post2
0.4.7
0.4.8
+ 66 more Show less
0.5.0
0.5.1
0.6.0
0.6.1
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.4.post0
0.7.4.post1
0.7.5.post1
0.7.5.post2
0.8.0
0.8.0.post0
0.8.1
0.8.1.post0
0.8.2
0.8.2.post0
0.9.0
0.9.0.post2
0.9.0.post3
0.9.0.post4
0.9.0.post5
0.9.1
0.9.1.post0
0.9.1.post1
0.9.1.post2
1.0.0
1.0.0.post0
1.0.0.post1
1.0.0.post2
1.0.0.post3
1.0.1
1.0.2
1.0.2.post0
1.1.0
1.1.0rc0
1.1.1
1.10.0
1.10.0.post0
1.2
1.3
1.3.post0
1.3.post1
1.4
1.4.1
1.4.1.post0
1.4.1.post1
1.5.0
1.5.0.post0
1.6.0
1.7.0
1.7.1
1.7.2
1.7.3
1.8.0
1.8.1
1.8.2
1.8.2.post0
1.8.2.post1
1.9.0
1.9.1
1.9.1.post0
1.9.2
1.9.2.post0
Fixed in
1.10.1
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2023-47115
GHSA-q68h-xwq5-mm7x
PYSEC-2024-126
Jan 24, 2024
Cross-site Scripting Vulnerability on Avatar Upload
7.1
/ 10
High
Network
Low
None
Required
Changed
Low
Low
Low
IntroductionThis write-up describes a vulnerability found in Label Studio, a popular open source data labeling tool. The vulnerability affects all versions of Label Studio prior to OverviewLabel Studio has a cross-site scripting (XSS) vulnerability that could be exploited when an authenticated user uploads a crafted image file for their avatar that gets rendered as a HTML file on the website. DescriptionThe following code snippet in Label Studio shows that the only verification check is that the file is an image by extracting the dimensions from the file.
Label Studio serves avatar images using Django's built-in
The issue with the Django Proof of ConceptBelow are the steps to reproduce this issue and execute JavaScript code in the context of the Label Studio website.
ImpactExecuting arbitrary JavaScript could result in an attacker performing malicious actions on Label Studio users if they visit the crafted avatar image. For an example, an attacker can craft a JavaScript payload that adds a new Django Super Administrator user if a Django administrator visits the image. Remediation Advice
Discovered
Affected versions
0.4.1
0.4.2
0.4.3
0.4.4
0.4.4.post1
0.4.4.post2
0.4.5
0.4.6
0.4.6.post1
0.4.6.post2
0.4.7
0.4.8
+ 62 more Show less
0.5.0
0.5.1
0.6.0
0.6.1
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.4.post0
0.7.4.post1
0.7.5.post1
0.7.5.post2
0.8.0
0.8.0.post0
0.8.1
0.8.1.post0
0.8.2
0.8.2.post0
0.9.0
0.9.0.post2
0.9.0.post3
0.9.0.post4
0.9.0.post5
0.9.1
0.9.1.post0
0.9.1.post1
0.9.1.post2
1.0.0
1.0.0.post0
1.0.0.post1
1.0.0.post2
1.0.0.post3
1.0.1
1.0.2
1.0.2.post0
1.1.0
1.1.0rc0
1.1.1
1.2
1.3
1.3.post0
1.3.post1
1.4
1.4.1
1.4.1.post0
1.4.1.post1
1.5.0
1.5.0.post0
1.6.0
1.7.0
1.7.1
1.7.2
1.7.3
1.8.0
1.8.1
1.8.2
1.8.2.post0
1.8.2.post1
1.9.0
1.9.1
1.9.1.post0
Fixed in
1.9.2
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2023-47117
GHSA-6hjj-gq77-j4qw
PYSEC-2023-275
Nov 14, 2023
Label Studio Object Relational Mapper Leak Vulnerability in Filtering Task
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
IntroductionThis write-up describes a vulnerability found in Label Studio, a popular open source data labeling tool. The vulnerability affects all versions of Label Studio prior to OverviewIn all current versions of Label Studio, the application allows users to insecurely set filters for filtering tasks. An attacker can construct a filter chain to filter tasks based on sensitive fields for all user accounts on the platform by exploiting Django's Object Relational Mapper (ORM). Since the results of query can be manipulated by the ORM filter, an attacker can leak these sensitive fields character by character. For an example, the following filter chain will task results by the password hash of an account on Label Studio.
For consistency, this type of vulnerability will be termed as ORM Leak in the rest of this disclosure. In addition, Label Studio had a hard coded secret key that an attacker can use to forge a session token of any user by exploiting this ORM Leak vulnerability to leak account password hashes. DescriptionThe following code snippet from the
These
The
The following code snippet of the
Finally, the
Proof of ConceptBelow are the steps to exploit about how to exploit this vulnerability to leak the password hash of an account on Label Studio.
The following example GIF demonstrates exploiting this ORM Leak vulnerability to retrieve the password hash
ImpactThis vulnerability can be exploited to completely compromise the confidentiality of highly sensitive account information, such as account password hashes. For all versions Remediation Advice
Discovered
| ||
1.0.2
patch
12 CVEs
CVE-2026-22033
PYSEC-2026-1502
GHSA-2mq9-hm29-8qch
Jul 07, 2026
Label Studio is vulnerable to full account takeover by chaining Stored XSS + IDOR in User Profile via custom_hotkeys field
Critical
Network
Low
Low
None
PrologueThese vulnerabilities have been found and chained by DCODX-AI. Validation of the exploit chain has been confirmed manually. SummaryA persistent stored cross-site scripting (XSS) vulnerability exists in the custom_hotkeys functionality of the application. An authenticated attacker (or one who can trick a user/administrator into updating their custom_hotkeys) can inject JavaScript code that executes in other users’ browsers when those users load any page using the DetailsWithin
Here, user.custom_hotkeys is run through json_dumps_ensure_ascii (in In
The serializer allows
When another user loads a page using templates/base.html (for example PoC
Example request
Example response
ImpactExploitation impact:
Who is impacted:
Affected versions
0.4.1
0.4.2
0.4.3
0.4.4
0.4.4.post1
0.4.4.post2
0.4.5
0.4.6
0.4.6.post1
0.4.6.post2
0.4.7
0.4.8
+ 83 more Show less
0.5.0
0.5.1
0.6.0
0.6.1
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.4.post0
0.7.4.post1
0.7.5.post1
0.7.5.post2
0.8.0
0.8.0.post0
0.8.1
0.8.1.post0
0.8.2
0.8.2.post0
0.9.0
0.9.0.post2
0.9.0.post3
0.9.0.post4
0.9.0.post5
0.9.1
0.9.1.post0
0.9.1.post1
0.9.1.post2
1.0.0
1.0.0.post0
1.0.0.post1
1.0.0.post2
1.0.0.post3
1.0.1
1.0.2
1.0.2.post0
1.1.0
1.1.0rc0
1.1.1
1.10.0
1.10.0.post0
1.10.1
1.11.0
1.12.0
1.12.0.post0
1.12.1
1.13.0
1.13.1
1.14.0
1.14.0.post0
1.15.0
1.16.0
1.17.0
1.18.0
1.19.0
1.2
1.20.0
1.21.0
1.22.0
1.3
1.3.post0
1.3.post1
1.4
1.4.1
1.4.1.post0
1.4.1.post1
1.5.0
1.5.0.post0
1.6.0
1.7.0
1.7.1
1.7.2
1.7.3
1.8.0
1.8.1
1.8.2
1.8.2.post0
1.8.2.post1
1.9.0
1.9.1
1.9.1.post0
1.9.2
1.9.2.post0
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-25297
PYSEC-2026-1503
GHSA-m238-fmcw-wh58
Jul 07, 2026
Label Studio allows Server-Side Request Forgery in the S3 Storage Endpoint
8.6
/ 10
High
Network
Low
None
None
Changed
High
None
None
DescriptionLabel Studio's S3 storage integration feature contains a Server-Side Request Forgery (SSRF) vulnerability in its endpoint configuration. When creating an S3 storage connection, the application allows users to specify a custom S3 endpoint URL via the s3_endpoint parameter. This endpoint URL is passed directly to the boto3 AWS SDK without proper validation or restrictions on the protocol or destination. The vulnerability allows an attacker to make the application send HTTP requests to arbitrary internal services by specifying them as the S3 endpoint. When the storage sync operation is triggered, the application attempts to make S3 API calls to the specified endpoint, effectively making HTTP requests to the target service and returning the response in error messages. This SSRF vulnerability enables attackers to bypass network segmentation and access internal services that should not be accessible from the external network. The vulnerability is particularly severe because error messages from failed requests contain the full response body, allowing data exfiltration from internal services. Steps to reproduce
The application will attempt to connect to the specified endpoint URL as if it were an S3 service. When the request fails due to invalid S3 API responses, the error message will contain the raw response from the internal service, allowing access to internal resources. Mitigations
ImpactThis vulnerability has high severity as it allows authenticated users to make requests to arbitrary internal services from the application server, potentially exposing sensitive internal resources and bypassing network segmentation. The inclusion of response data in error messages makes this particularly effective for data exfiltration. Affected versions
0.4.1
0.4.2
0.4.3
0.4.4
0.4.4.post1
0.4.4.post2
0.4.5
0.4.6
0.4.6.post1
0.4.6.post2
0.4.7
0.4.8
+ 76 more Show less
0.5.0
0.5.1
0.6.0
0.6.1
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.4.post0
0.7.4.post1
0.7.5.post1
0.7.5.post2
0.8.0
0.8.0.post0
0.8.1
0.8.1.post0
0.8.2
0.8.2.post0
0.9.0
0.9.0.post2
0.9.0.post3
0.9.0.post4
0.9.0.post5
0.9.1
0.9.1.post0
0.9.1.post1
0.9.1.post2
1.0.0
1.0.0.post0
1.0.0.post1
1.0.0.post2
1.0.0.post3
1.0.1
1.0.2
1.0.2.post0
1.1.0
1.1.0rc0
1.1.1
1.10.0
1.10.0.post0
1.10.1
1.11.0
1.12.0
1.12.0.post0
1.12.1
1.13.0
1.13.1
1.14.0
1.14.0.post0
1.15.0
1.2
1.3
1.3.post0
1.3.post1
1.4
1.4.1
1.4.1.post0
1.4.1.post1
1.5.0
1.5.0.post0
1.6.0
1.7.0
1.7.1
1.7.2
1.7.3
1.8.0
1.8.1
1.8.2
1.8.2.post0
1.8.2.post1
1.9.0
1.9.1
1.9.1.post0
1.9.2
1.9.2.post0
Fixed in
1.16.0
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-25296
PYSEC-2026-1504
GHSA-wpq5-3366-mqw4
Jul 07, 2026
Label Studio allows Cross-Site Scripting (XSS) via GET request to `/projects/upload-example` endpoint
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
DescriptionLabel Studio's The vulnerability exists because the upload-example endpoint renders user-provided HTML content without proper sanitization on a GET request. This allows attackers to inject and execute arbitrary JavaScript in victims' browsers by getting them to visit a maliciously crafted URL. This is considered vulnerable because it enables attackers to execute JavaScript in victims' contexts, potentially allowing theft of sensitive data, session hijacking, or other malicious actions. Steps to reproduce
When executed, the payload causes the application to render an HTML page containing an img tag that fails to load, triggering the onerror event handler which executes base64-decoded JavaScript, demonstrating successful XSS execution in the victim's browser. Mitigations
ImpactThe vulnerability requires no special privileges and can be exploited by getting a victim to visit a crafted URL. The impact is high as it allows arbitrary JavaScript execution in victims' browsers, potentially exposing sensitive data or enabling account takeover through session theft. Affected versions
0.4.1
0.4.2
0.4.3
0.4.4
0.4.4.post1
0.4.4.post2
0.4.5
0.4.6
0.4.6.post1
0.4.6.post2
0.4.7
0.4.8
+ 76 more Show less
0.5.0
0.5.1
0.6.0
0.6.1
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.4.post0
0.7.4.post1
0.7.5.post1
0.7.5.post2
0.8.0
0.8.0.post0
0.8.1
0.8.1.post0
0.8.2
0.8.2.post0
0.9.0
0.9.0.post2
0.9.0.post3
0.9.0.post4
0.9.0.post5
0.9.1
0.9.1.post0
0.9.1.post1
0.9.1.post2
1.0.0
1.0.0.post0
1.0.0.post1
1.0.0.post2
1.0.0.post3
1.0.1
1.0.2
1.0.2.post0
1.1.0
1.1.0rc0
1.1.1
1.10.0
1.10.0.post0
1.10.1
1.11.0
1.12.0
1.12.0.post0
1.12.1
1.13.0
1.13.1
1.14.0
1.14.0.post0
1.15.0
1.2
1.3
1.3.post0
1.3.post1
1.4
1.4.1
1.4.1.post0
1.4.1.post1
1.5.0
1.5.0.post0
1.6.0
1.7.0
1.7.1
1.7.2
1.7.3
1.8.0
1.8.1
1.8.2
1.8.2.post0
1.8.2.post1
1.9.0
1.9.1
1.9.1.post0
1.9.2
1.9.2.post0
Fixed in
1.16.0
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-47783
GHSA-8jhr-wpcm-hh4h
PYSEC-2025-124
May 15, 2025
label-studio vulnerable to Cross-Site Scripting (Reflected) via the label_config parameter.
High
Network
Low
None
SummaryThe vulnerability allows an attacker to inject a malicious script into the context of a web page, which can lead to data theft, unauthorized actions on behalf of the user, and other attacks. DetailsThe vulnerability is reproducible when sending a properly formatted request to the
The vulnerability is specifically located in line 57, where HttpResponse is used.
PoCSend the following request after changing the
Or you can create a vulnerable HTML page by changing
Impact
Affected versions
0.4.1
0.4.2
0.4.3
0.4.4
0.4.4.post1
0.4.4.post2
0.4.5
0.4.6
0.4.6.post1
0.4.6.post2
0.4.7
0.4.8
+ 78 more Show less
0.5.0
0.5.1
0.6.0
0.6.1
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.4.post0
0.7.4.post1
0.7.5.post1
0.7.5.post2
0.8.0
0.8.0.post0
0.8.1
0.8.1.post0
0.8.2
0.8.2.post0
0.9.0
0.9.0.post2
0.9.0.post3
0.9.0.post4
0.9.0.post5
0.9.1
0.9.1.post0
0.9.1.post1
0.9.1.post2
1.0.0
1.0.0.post0
1.0.0.post1
1.0.0.post2
1.0.0.post3
1.0.1
1.0.2
1.0.2.post0
1.1.0
1.1.0rc0
1.1.1
1.10.0
1.10.0.post0
1.10.1
1.11.0
1.12.0
1.12.0.post0
1.12.1
1.13.0
1.13.1
1.14.0
1.14.0.post0
1.15.0
1.16.0
1.17.0
1.2
1.3
1.3.post0
1.3.post1
1.4
1.4.1
1.4.1.post0
1.4.1.post1
1.5.0
1.5.0.post0
1.6.0
1.7.0
1.7.1
1.7.2
1.7.3
1.8.0
1.8.1
1.8.2
1.8.2.post0
1.8.2.post1
1.9.0
1.9.1
1.9.1.post0
1.9.2
1.9.2.post0
Fixed in
1.18.0
References
Updated Jun 06, 2026 · Source: OSV.dev
CVE-2024-26152
PYSEC-2024-249
GHSA-6xv9-957j-qfhg
Feb 22, 2024
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
SummaryOn all Label Studio versions prior to 1.11.0, data imported via file upload feature is not properly sanitized prior to being rendered within a DetailsNeed permission to use the "data import" function. This was reproduced on Label Studio 1.10.1. PoC
The following are the contents of the files used in the PoC
ImpactMalicious scripts can be injected into the code, and when linked with vulnerabilities such as CSRF, it can cause even greater damage. In particular, It can become a source of further attacks, especially when linked to social engineering. Affected versions
0.4.1
0.4.2
0.4.3
0.4.4
0.4.4.post1
0.4.4.post2
0.4.5
0.4.6
0.4.6.post1
0.4.6.post2
0.4.7
0.4.8
+ 113 more Show less
0.5.0
0.5.1
0.6.0
0.6.1
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.4.post0
0.7.4.post1
0.7.5.post1
0.7.5.post2
0.8.0
0.8.0.post0
0.8.1
0.8.1.post0
0.8.2
0.8.2.post0
0.9.0
0.9.0.post2
0.9.0.post3
0.9.0.post4
0.9.0.post5
0.9.1
0.9.1.post0
0.9.1.post1
0.9.1.post2
1.0.0
1.0.0.post0
1.0.0.post1
1.0.0.post2
1.0.0.post3
1.0.1
1.0.2
1.0.2.post0
1.1.0
1.1.0rc0
1.1.1
1.10.0
1.10.0.post0
1.10.1
1.2
1.3
1.3.post0
1.3.post1
1.4
1.4.1
1.4.1.post0
1.4.1.post1
1.5.0
1.5.0.post0
1.6.0
1.7.0
1.7.1
1.7.2
1.7.3
1.8.0
1.8.1
1.8.2
1.8.2.post0
1.8.2.post1
1.9.0
1.9.1
1.9.1.post0
1.9.2
1.9.2.post0
v1.4.1
v1.4.0
v1.3.0
v1.2.0
v1.1.1
v1.1.0
v1.0.2
v1.0.1
v1.0.0
v0.9.1.post1
v0.9.1.post0
v0.9.0.post5
v0.9.0.post4
v0.9.0.post3
v0.9.0
v0.8.2
v0.8.1
v0.8.0
v0.7.5.post0
v0.7.3
v0.7.2
v0.7.1
v0.7.0
v0.6.1
v0.6.0
v0.5.1
v0.4.8
v0.4.7
v0.4.6
v0.4.5
v0.4.4
v0.4.0
v0.3.0
v0.2.2
v.0.2.1-8
v.0.2.1-5
v.0.2.1-4
v.0.2.1-3
v.0.2.1-2
v.0.2.0
v.0.1.6
v.0.1.5
v.0.1.4
v.0.1.2
v.0.1.1
v.0.1.0
Fixed in
1.11.0
References
Updated Jun 10, 2026 · Source: OSV.dev
CVE-2023-47116
GHSA-p59w-9gqw-wj8r
PYSEC-2024-127
Jan 31, 2024
Label Studio SSRF on Import Bypassing `SSRF_PROTECTION_ENABLED` Protections
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
IntroductionThis write-up describes a vulnerability found in Label Studio, a popular open source data labeling tool. The vulnerability affects all versions of Label Studio prior to OverviewLabel Studio's SSRF protections that can be enabled by setting the DescriptionThe following
The
The issue here is the SSRF validation is only performed before the request is sent, and does not validate the destination IP address. Therefore, an attacker can either redirect the request or perform a DNS rebinding attack to bypass this protection. Proof of ConceptBoth the HTTP redirection and DNS rebinding methods for bypassing Label Studio's SSRF protections are explained below. HTTP RedirectionThe python
DNS Rebinding AttackDNS rebinding can bypass SSRF protections by resolving to an external IP address for the first resolution, but when the request is sent resolves to an internal IP address that is blocked. For an example, the domain ImpactSSRF vulnerabilities pose a significant risk on cloud environments, since instance credentials are managed by internal web APIs. An attacker can bypass Label Studio's SSRF protections to access internal web servers and partially compromise the confidentiality of those internal servers. Remediation Advice
Discovered
Affected versions
0.4.1
0.4.2
0.4.3
0.4.4
0.4.4.post1
0.4.4.post2
0.4.5
0.4.6
0.4.6.post1
0.4.6.post2
0.4.7
0.4.8
+ 67 more Show less
0.5.0
0.5.1
0.6.0
0.6.1
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.4.post0
0.7.4.post1
0.7.5.post1
0.7.5.post2
0.8.0
0.8.0.post0
0.8.1
0.8.1.post0
0.8.2
0.8.2.post0
0.9.0
0.9.0.post2
0.9.0.post3
0.9.0.post4
0.9.0.post5
0.9.1
0.9.1.post0
0.9.1.post1
0.9.1.post2
1.0.0
1.0.0.post0
1.0.0.post1
1.0.0.post2
1.0.0.post3
1.0.1
1.0.2
1.0.2.post0
1.1.0
1.1.0rc0
1.1.1
1.10.0
1.10.0.post0
1.10.1
1.2
1.3
1.3.post0
1.3.post1
1.4
1.4.1
1.4.1.post0
1.4.1.post1
1.5.0
1.5.0.post0
1.6.0
1.7.0
1.7.1
1.7.2
1.7.3
1.8.0
1.8.1
1.8.2
1.8.2.post0
1.8.2.post1
1.9.0
1.9.1
1.9.1.post0
1.9.2
1.9.2.post0
Fixed in
1.11.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-23633
GHSA-fq23-g58m-799r
PYSEC-2024-128
Jan 24, 2024
Cross-site Scripting Vulnerability on Data Import
4.7
/ 10
Medium
Network
Low
None
Required
Changed
Low
None
None
IntroductionThis write-up describes a vulnerability found in Label Studio, a popular open source data labeling tool. The vulnerability affects all versions of Label Studio prior to OverviewLabel Studio had a remote import feature allowed users to import data from a remote web source, that was downloaded and could be viewed on the website. This feature could had been abused to download a HTML file that executed malicious JavaScript code in the context of the Label Studio website. DescriptionThe following code snippet in Label Studio showed that is a URL passed the SSRF verification checks, the contents of the file would be downloaded using the filename in the URL.
The downloaded file path could then be retrieved by sending a request to
Since the Proof of ConceptBelow were the steps to recreate this issue:
ImpactExecuting arbitrary JavaScript could result in an attacker performing malicious actions on Label Studio users if they visit the crafted avatar image. For an example, an attacker can craft a JavaScript payload that adds a new Django Super Administrator user if a Django administrator visits the image. Remediation Advice
Discovered
Affected versions
0.4.1
0.4.2
0.4.3
0.4.4
0.4.4.post1
0.4.4.post2
0.4.5
0.4.6
0.4.6.post1
0.4.6.post2
0.4.7
0.4.8
+ 66 more Show less
0.5.0
0.5.1
0.6.0
0.6.1
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.4.post0
0.7.4.post1
0.7.5.post1
0.7.5.post2
0.8.0
0.8.0.post0
0.8.1
0.8.1.post0
0.8.2
0.8.2.post0
0.9.0
0.9.0.post2
0.9.0.post3
0.9.0.post4
0.9.0.post5
0.9.1
0.9.1.post0
0.9.1.post1
0.9.1.post2
1.0.0
1.0.0.post0
1.0.0.post1
1.0.0.post2
1.0.0.post3
1.0.1
1.0.2
1.0.2.post0
1.1.0
1.1.0rc0
1.1.1
1.10.0
1.10.0.post0
1.2
1.3
1.3.post0
1.3.post1
1.4
1.4.1
1.4.1.post0
1.4.1.post1
1.5.0
1.5.0.post0
1.6.0
1.7.0
1.7.1
1.7.2
1.7.3
1.8.0
1.8.1
1.8.2
1.8.2.post0
1.8.2.post1
1.9.0
1.9.1
1.9.1.post0
1.9.2
1.9.2.post0
Fixed in
1.10.1
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2023-47115
GHSA-q68h-xwq5-mm7x
PYSEC-2024-126
Jan 24, 2024
Cross-site Scripting Vulnerability on Avatar Upload
7.1
/ 10
High
Network
Low
None
Required
Changed
Low
Low
Low
IntroductionThis write-up describes a vulnerability found in Label Studio, a popular open source data labeling tool. The vulnerability affects all versions of Label Studio prior to OverviewLabel Studio has a cross-site scripting (XSS) vulnerability that could be exploited when an authenticated user uploads a crafted image file for their avatar that gets rendered as a HTML file on the website. DescriptionThe following code snippet in Label Studio shows that the only verification check is that the file is an image by extracting the dimensions from the file.
Label Studio serves avatar images using Django's built-in
The issue with the Django Proof of ConceptBelow are the steps to reproduce this issue and execute JavaScript code in the context of the Label Studio website.
ImpactExecuting arbitrary JavaScript could result in an attacker performing malicious actions on Label Studio users if they visit the crafted avatar image. For an example, an attacker can craft a JavaScript payload that adds a new Django Super Administrator user if a Django administrator visits the image. Remediation Advice
Discovered
Affected versions
0.4.1
0.4.2
0.4.3
0.4.4
0.4.4.post1
0.4.4.post2
0.4.5
0.4.6
0.4.6.post1
0.4.6.post2
0.4.7
0.4.8
+ 62 more Show less
0.5.0
0.5.1
0.6.0
0.6.1
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.4.post0
0.7.4.post1
0.7.5.post1
0.7.5.post2
0.8.0
0.8.0.post0
0.8.1
0.8.1.post0
0.8.2
0.8.2.post0
0.9.0
0.9.0.post2
0.9.0.post3
0.9.0.post4
0.9.0.post5
0.9.1
0.9.1.post0
0.9.1.post1
0.9.1.post2
1.0.0
1.0.0.post0
1.0.0.post1
1.0.0.post2
1.0.0.post3
1.0.1
1.0.2
1.0.2.post0
1.1.0
1.1.0rc0
1.1.1
1.2
1.3
1.3.post0
1.3.post1
1.4
1.4.1
1.4.1.post0
1.4.1.post1
1.5.0
1.5.0.post0
1.6.0
1.7.0
1.7.1
1.7.2
1.7.3
1.8.0
1.8.1
1.8.2
1.8.2.post0
1.8.2.post1
1.9.0
1.9.1
1.9.1.post0
Fixed in
1.9.2
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2023-47117
GHSA-6hjj-gq77-j4qw
PYSEC-2023-275
Nov 14, 2023
Label Studio Object Relational Mapper Leak Vulnerability in Filtering Task
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
IntroductionThis write-up describes a vulnerability found in Label Studio, a popular open source data labeling tool. The vulnerability affects all versions of Label Studio prior to OverviewIn all current versions of Label Studio, the application allows users to insecurely set filters for filtering tasks. An attacker can construct a filter chain to filter tasks based on sensitive fields for all user accounts on the platform by exploiting Django's Object Relational Mapper (ORM). Since the results of query can be manipulated by the ORM filter, an attacker can leak these sensitive fields character by character. For an example, the following filter chain will task results by the password hash of an account on Label Studio.
For consistency, this type of vulnerability will be termed as ORM Leak in the rest of this disclosure. In addition, Label Studio had a hard coded secret key that an attacker can use to forge a session token of any user by exploiting this ORM Leak vulnerability to leak account password hashes. DescriptionThe following code snippet from the
These
The
The following code snippet of the
Finally, the
Proof of ConceptBelow are the steps to exploit about how to exploit this vulnerability to leak the password hash of an account on Label Studio.
The following example GIF demonstrates exploiting this ORM Leak vulnerability to retrieve the password hash
ImpactThis vulnerability can be exploited to completely compromise the confidentiality of highly sensitive account information, such as account password hashes. For all versions Remediation Advice
Discovered
|



