PT-2025-21251 · Unknown · Label Studio

Medok228

·

Published

2025-05-14

·

Updated

2025-05-19

·

CVE-2025-47783

CVSS v4.0

7.6

High

VectorAV:N/AC:L/AT:P/PR:N/UI:P/VC:H/VI:H/VA:N/SC:L/SI:L/SA:N
Name of the Vulnerable Software and Affected Versions: Label Studio versions prior to 1.18.0
Description: A vulnerability in Label Studio allows an attacker to inject a malicious script into the context of a web page, which can lead to data theft, session hijacking, unauthorized actions on behalf of the user, and other attacks. The issue is reproducible when sending a properly formatted request to the "POST /projects/upload-example/" endpoint. The vulnerability is located at label studio/projects/views.py and is related to the label config parameter.
Recommendations: For versions prior to 1.18.0, update to version 1.18.0, which contains a patch for the issue. As a temporary workaround, consider restricting access to the POST /projects/upload-example/ endpoint and avoiding the use of the label config parameter until the update is applied.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-47783
GHSA-8JHR-WPCM-HH4H
PYSEC-2025-124

Affected Products

Label Studio