VendorsHumansignallabel_studioall versions
Vulnerabilities

Humansignal Label Studio 1.9.2 -

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

10CVEs
CVE-2023-43791
Label Studio has Hardcoded Django `SECRET_KEY` that can be Abused to Forge Session Tokens
Published 2023-11-09 · Modified
9.8EPSS 0.012
CVE-2025-25297
Label Studio allows Server-Side Request Forgery in the S3 Storage Endpoint
Published 2025-02-14 · Analyzed
8.6EPSS 0.007
CVE-2026-22033
Label Studio vulnerable to full account takeover by chaining Stored XSS + IDOR in User Profile via custom_hotkeys field
Published 2026-01-12 · Analyzed
8.6EPSS 0.003
CVE-2025-47783
label-studio vulnerable to Cross-Site Scripting (Reflected) via the label_config parameter.
Published 2025-05-14 · Analyzed
7.6EPSS 0.006
CVE-2023-47117
Object Relational Mapper Leak Vulnerability in Filtering Task in Label Studio
Published 2023-11-13 · Modified
7.5EPSS 0.041
CVE-2023-47115
Label Studio XSS Vulnerability on Avatar Upload
Published 2024-01-23 · Modified
7.1EPSS 0.014
CVE-2024-26152
Label Studio vulnerable to Cross-site Scripting if `<Choices>` or `<Labels>` are used in labeling config
Published 2024-02-22 · Analyzed
6.1EPSS 0.022
CVE-2025-25296
Label Studio allows Cross-Site Scripting (XSS) via GET request to `/projects/upload-example` endpoint
Published 2025-02-14 · Analyzed
6.1EPSS 0.019
CVE-2024-23633
Label Studio XSS Vulnerability on Data Import
Published 2024-01-23 · Modified
6.1EPSS 0.006
CVE-2023-47116
Label Studio SSRF on Import Bypassing `SSRF_PROTECTION_ENABLED` Protections
Published 2024-01-31 · Modified
5.3EPSS 0.007