Known Vulnerabilities for Label Studio by HumanSignal
Listed below are 4 of the newest known vulnerabilities associated with "Label Studio" by "HumanSignal".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-85211 json | Label Studio fails to apply organization filters when resolving storage URIs for tasks and projects in proxy_api.py endpoints... | Not Provided | 2026-09-03 | 2026-09-03 |
| CVE-2026-85179 json | Label Studio through 1.23.0 fails to validate webhook URLs, allowing authenticated users to dispatch requests to internal ser... | Not Provided | 2026-09-03 | 2026-09-03 |
| CVE-2026-76073 json | Label Studio does not scope the annotation detail endpoint to the requesting user's organization. AnnotationAPI in label_stud... | Not Provided | 2026-08-24 | 2026-08-26 |
| CVE-2026-72560 json | A server-side request forgery vulnerability in HumanSignal Label Studio through 1.24.0.dev0 exists because SSRF_PROTECTION_EN... | Not Provided | 2026-08-11 | 2026-08-11 |
| CVE-2024-23633 json | 6.1 - MEDIUM | 2024-01-24 | 2024-02-01 | |
| CVE-2023-47117 json | ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new secur... | 7.5 - HIGH | 2023-11-13 | 2023-11-20 |
| CVE-2023-47115 json | ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new secur... | 5.4 - MEDIUM | 2024-01-23 | 2024-02-01 |
| CVE-2023-43791 json | ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new secur... | 8.8 - HIGH | 2023-11-09 | 2023-11-18 |
| CVE-2022-36551 json | A Server Side Request Forgery (SSRF) in the Data Import module in Heartex - Label Studio Community Edition versions 1.5.0 and... | 8.8 - HIGH | 2022-10-03 | 2026-07-09 |