Executive brief
Label Studio is a data labeling and annotation platform used by organizations to prepare training data. A misconfiguration in the default setup allows authenticated users to access internal network services and cloud metadata endpoints through the URL import feature, potentially exposing sensitive credentials and internal infrastructure details.
Technical details
This vulnerability is a server-side request forgery (SSRF) in the import-from-URL endpoint caused by SSRF_PROTECTION_ENABLED being set to false by default. An authenticated user can supply arbitrary URLs, including loopback addresses (127.0.0.1) and internal cloud metadata endpoints (e.g., AWS IMDSv1), which the server will fetch and return. The attack requires authentication but no additional preconditions. An attacker can reach internal services not intended for external access, enumerate network topology, and exfiltrate cloud credentials. No information on patch availability is provided in the advisory.
Affected products
- HumanSignal Label Studio through 1.24.0.dev0
Timeline
- 2026-08-11: disclosed