PT-2025-21251 · Unknown · Label Studio
Medok228
·
Published
2025-05-14
·
Updated
2025-05-19
·
CVE-2025-47783
CVSS v4.0
7.6
High
| Vector | AV:N/AC:L/AT:P/PR:N/UI:P/VC:H/VI:H/VA:N/SC:L/SI:L/SA:N |
Name of the Vulnerable Software and Affected Versions:
Label Studio versions prior to 1.18.0
Description:
A vulnerability in Label Studio allows an attacker to inject a malicious script into the context of a web page, which can lead to data theft, session hijacking, unauthorized actions on behalf of the user, and other attacks. The issue is reproducible when sending a properly formatted request to the "POST /projects/upload-example/" endpoint. The vulnerability is located at
label studio/projects/views.py and is related to the label config parameter.Recommendations:
For versions prior to 1.18.0, update to version 1.18.0, which contains a patch for the issue. As a temporary workaround, consider restricting access to the
POST /projects/upload-example/ endpoint and avoiding the use of the label config parameter until the update is applied.Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Label Studio