Executive brief
Label Studio, a popular open-source data labeling platform, is vulnerable to a security flaw that allows attackers to run malicious scripts in a user's browser. By tricking a user into clicking a link or visiting a malicious website, an attacker could perform unauthorized actions on the user's behalf within the application. While session cookies are protected, this could still lead to data exposure or unauthorized modifications to labeling projects.
Technical details
A reflected Cross-Site Scripting (XSS) vulnerability exists in Label Studio's `POST /projects/upload-example/` endpoint. The root cause is located in `label_studio/projects/views.py`, where the `label_config` POST parameter is processed and subsequently returned in an `HttpResponse` using `json.dumps()` without sufficient sanitization or proper Content-Type headers to prevent browser execution. An attacker can exploit this by crafting a malicious request (e.g., via a hidden form on a third-party site) that executes arbitrary JavaScript in the victim's browser session. While `HttpOnly` flags on session cookies mitigate direct session hijacking, the attacker can still perform any action the user is authorized to do. The vulnerability is patched in version 1.18.0.
Affected products
- HumanSignal label-studio < 1.18.0
Timeline
- 2025-05-14: disclosed
- 2025-05-15: advisory: GitHub Advisory published
- 1.18.0: patched