📦 Label Studio

by Humansignal

🔍 What is Label Studio?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2023-43791

CRITICAL CVSS 9.8 Nov 9, 2023

CVE-2023-43791 is a privilege escalation vulnerability in Label Studio that allows attackers to chain an ORM leak vulnerability with other flaws to impersonate any account, including Django Super Admi...

CVE-2025-25297

HIGH CVSS 8.6 Feb 14, 2025

Label Studio versions before 1.16.0 contain a Server-Side Request Forgery (SSRF) vulnerability in the S3 storage integration feature. Attackers can exploit this by specifying arbitrary internal servic...

CVE-2023-47117

HIGH CVSS 7.5 Nov 13, 2023

This vulnerability in Label Studio allows attackers to exploit insecure filter chains to leak sensitive user data character by character through Django ORM manipulation. Attackers can also forge sessi...

CVE-2026-22033

MEDIUM CVSS 5.4 Jan 12, 2026

This is a persistent stored XSS vulnerability in Label Studio's custom_hotkeys functionality that allows authenticated attackers to inject malicious JavaScript. When executed in victims' browsers, the...

CVE-2025-25296

MEDIUM CVSS 6.1 Feb 14, 2025

This vulnerability allows attackers to inject malicious HTML/JavaScript through Label Studio's upload-example endpoint, enabling Cross-Site Scripting (XSS) attacks. Anyone using Label Studio versions ...