Product
humansignal label studio
11 known vulnerabilities across versions
Vulnerabilities are listed by affected version. Select any CVE for the full briefing and its intelligence graph.
CVE-2026-22033
CVE-2025-47783
CVE-2025-25297
CVE-2025-25296
CVE-2024-26152
CVE-2023-47116
CVE-2024-23633
CVE-2023-47115
CVE-2023-47117
CVE-2023-43791
CVE-2022-36551
<= 1.22.0
Label Studio is a multi-type data labeling and annotation tool. In 1.22.0 and earlier, a persistent stored cross-site scripting (X
< 1.18.0
Label Studio is a multi-type data labeling and annotation tool. A vulnerability in versions prior to 1.18.0 allows an attacker to
< 1.16.0
Label Studio is an open source data labeling tool. Prior to version 1.16.0, Label Studio's S3 storage integration feature contains
< 1.16.0
Label Studio is an open source data labeling tool. Prior to version 1.16.0, Label Studio's
/projects/upload-example endpoint all< 1.11.0
### Summary On all Label Studio versions prior to 1.11.0, data imported via file upload feature is not properly sanitized prior to
< 1.11.0
Label Studio is a popular open source data labeling tool. The vulnerability affects all versions of Label Studio prior to 1.11.0 a
< 1.10.1
Label Studio, an open source data labeling tool had a remote import feature allowed users to import data from a remote web source,
< 1.9.2
Label Studio is an a popular open source data labeling tool. Versions prior to 1.9.2 have a cross-site scripting (XSS) vulnerabili
< 1.9.2
Label Studio is an open source data labeling tool. In all current versions of Label Studio prior to 1.9.2post0, the application al
< 1.8.2
Label Studio is a multi-type data labeling and annotation tool with standardized output format. There is a vulnerability that can
<= 1.5.0
A Server Side Request Forgery (SSRF) in the Data Import module in Heartex - Label Studio Community Edition versions 1.5.0 and earl