VulnSea

label-studio has 8 CVEs on record between 2023 and 2026. The median CVSS is 7.1 (high). None have a confirmed exploitation report.

CVEs per month

Last 12 months, by publish date

101112010203040506070809
Exploited share
0% vs 1% corpus
Median CVSS
7.1
Publish → KEV
Last 90 days
0 prev 0

Products

  • label-studio 8
8
Total CVEs
0
Critical
0
CISA KEV
0
Exploited

label-studio vulnerabilities

CVEs affecting label-studio, newest first. Open any entry for full detail, references, and exploit status.

8 CVEsRSS

CVE-2026-22033High
8mo ago

Label Studio is vulnerable to full account takeover by chaining Stored XSS + IDOR in User Profile via custom_hotkeys field

Label Studio is vulnerable to full account takeover by chaining Stored XSS + IDOR in User Profile via custom_hotkeys field

Twilightlabel-studio · label-studioEPSS 0.28%via OSV
CVE-2025-25296Medium· 6.1PoC
1y ago

Label Studio allows Cross-Site Scripting (XSS) via GET request to `/projects/upload-example` endpoint

Label Studio allows Cross-Site Scripting (XSS) via GET request to `/projects/upload-example` endpoint

Twilightlabel-studio · label-studioEPSS 1.9%via OSV
CVE-2025-25297High· 8.6
1y ago

Label Studio allows Server-Side Request Forgery in the S3 Storage Endpoint

Label Studio allows Server-Side Request Forgery in the S3 Storage Endpoint

Twilightlabel-studio · label-studioEPSS 0.67%via OSV
CVE-2023-47116Medium· 5.3
2y ago

Label Studio SSRF on Import Bypassing `SSRF_PROTECTION_ENABLED` Protections

Label Studio SSRF on Import Bypassing `SSRF_PROTECTION_ENABLED` Protections

Sunlitlabel-studio · label-studioEPSS 0.74%via OSV
CVE-2023-47115High· 7.1PoC
2y ago

Cross-site Scripting Vulnerability on Avatar Upload

Cross-site Scripting Vulnerability on Avatar Upload

Midnightlabel-studio · label-studioEPSS 1.4%via OSV
CVE-2024-23633Medium· 4.7
2y ago

Cross-site Scripting Vulnerability on Data Import

Cross-site Scripting Vulnerability on Data Import

Sunlitlabel-studio · label-studioEPSS 0.59%via OSV
CVE-2023-47117High· 7.5PoC
2y ago

Label Studio Object Relational Mapper Leak Vulnerability in Filtering Task

Label Studio Object Relational Mapper Leak Vulnerability in Filtering Task

Midnightlabel-studio · label-studioEPSS 4.1%via OSV
GHSA-cpmr-mw4j-99r7High· 7.5
3y ago

Nginx alias path traversal allows unauthenticated attackers to read all files on /label_studio/core/

Nginx alias path traversal allows unauthenticated attackers to read all files on /label_studio/core/

Twilightlabel-studio · label-studiovia OSV
label-studio vulnerabilities (CVEs) · VulnSea