Home/Product/humansignal label studio
Product

humansignal label studio

11 known vulnerabilities across versions
Vulnerabilities are listed by affected version. Select any CVE for the full briefing and its intelligence graph.
CVE-2026-22033
<= 1.22.0
Label Studio is a multi-type data labeling and annotation tool. In 1.22.0 and earlier, a persistent stored cross-site scripting (X
5.4MEDIUM
CVE-2025-47783
< 1.18.0
Label Studio is a multi-type data labeling and annotation tool. A vulnerability in versions prior to 1.18.0 allows an attacker to
6.1MEDIUM
CVE-2025-25297
< 1.16.0
Label Studio is an open source data labeling tool. Prior to version 1.16.0, Label Studio's S3 storage integration feature contains
8.6HIGH
CVE-2025-25296
< 1.16.0
Label Studio is an open source data labeling tool. Prior to version 1.16.0, Label Studio's /projects/upload-example endpoint all
6.1MEDIUM
CVE-2024-26152
< 1.11.0
### Summary On all Label Studio versions prior to 1.11.0, data imported via file upload feature is not properly sanitized prior to
4.7MEDIUM
CVE-2023-47116
< 1.11.0
Label Studio is a popular open source data labeling tool. The vulnerability affects all versions of Label Studio prior to 1.11.0 a
5.3MEDIUM
CVE-2024-23633
< 1.10.1
Label Studio, an open source data labeling tool had a remote import feature allowed users to import data from a remote web source,
4.7MEDIUM
CVE-2023-47115
< 1.9.2
Label Studio is an a popular open source data labeling tool. Versions prior to 1.9.2 have a cross-site scripting (XSS) vulnerabili
7.1HIGH
CVE-2023-47117
< 1.9.2
Label Studio is an open source data labeling tool. In all current versions of Label Studio prior to 1.9.2post0, the application al
7.5HIGH
CVE-2023-43791
< 1.8.2
Label Studio is a multi-type data labeling and annotation tool with standardized output format. There is a vulnerability that can
9.8CRITICAL
CVE-2022-36551
<= 1.5.0
A Server Side Request Forgery (SSRF) in the Data Import module in Heartex - Label Studio Community Edition versions 1.5.0 and earl
6.5MEDIUM
threatengine.sh