QID 997453
Date Published: 2024-02-26
QID 997453: Python (Pip) Security Update for label-studio (GHSA-6xv9-957j-qfhg)
On all Label Studio versions prior to 1.11.0, data imported via file upload feature is not properly sanitized prior to being rendered within a Choices or Labels tag, resulting in an XSS vulnerability.
Successful exploitation of this vulnerability could lead to a security breach or could affect integrity, availability, and confidentiality.
Solution
Refer to Github security advisory GHSA-6xv9-957j-qfhg for updates and patch information.
Vendor References
- GHSA-6xv9-957j-qfhg -
github.com/advisories/GHSA-6xv9-957j-qfhg
CVEs related to QID 997453
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-6xv9-957j-qfhg | label-studio |
|