{"schema_version":1,"title":"label-studio (PyPI) vulnerabilities","summary":"Junglewise Threat Intelligence has tracked 16 vulnerabilities in label-studio (PyPI): 0 in the last 7 days and 7 in the last 90 days, 0 of them critical and 0 exploited in the wild. The most recent, CVE-2026-85211, was published on 3 September 2026.","url":"https://junglewise.ai/threats/technologies/label-studio","json_url":"https://junglewise.ai/threats/technologies/label-studio.json","publisher":"Junglewise Threat Intelligence","license":"CC-BY-4.0","license_url":"https://creativecommons.org/licenses/by/4.0/","attribution":"Junglewise Threat Intelligence, https://junglewise.ai/threats/technologies/label-studio","sources":"NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories","kind":"technology","counts":{"high":5,"all_time":16,"critical":0,"exploited":0,"last_7_days":0,"last_30_days":2,"last_90_days":7,"last_365_days":7},"latest":[{"cve":"CVE-2026-85211","cvss":7.7,"epss":0.0042,"slug":"cve-2026-85211-label-studio-organization-filter-bypass-in-proxy-api-py","title":"Label Studio organization filter bypass in proxy_api.py","severity":"high","exploited":false,"published_at":"2026-09-03T15:17:40.257+00:00","url":"https://junglewise.ai/threats/cve-2026-85211-label-studio-organization-filter-bypass-in-proxy-api-py"},{"cve":"CVE-2026-85179","cvss":8.5,"epss":0.004,"slug":"cve-2026-85179-label-studio-webhook-url-validation-bypass","title":"Label Studio webhook URL validation bypass","severity":"high","exploited":false,"published_at":"2026-09-03T15:17:39.097+00:00","url":"https://junglewise.ai/threats/cve-2026-85179-label-studio-webhook-url-validation-bypass"},{"cve":"CVE-2026-76073","cvss":8.8,"epss":0.0052,"slug":"cve-2026-76073-label-studio-annotation-api-missing-organization-scope-check","title":"Label Studio annotation API missing organization scope check","severity":"high","exploited":false,"published_at":"2026-08-24T18:17:21.41+00:00","url":"https://junglewise.ai/threats/cve-2026-76073-label-studio-annotation-api-missing-organization-scope-check"},{"cve":"CVE-2026-72560","cvss":6.5,"epss":0.0034,"slug":"cve-2026-72560-humansignal-label-studio-server-side-request-forgery-in-url","title":"HumanSignal Label Studio server-side request forgery in URL import","severity":"medium","exploited":false,"published_at":"2026-08-11T12:17:41.953+00:00","url":"https://junglewise.ai/threats/cve-2026-72560-humansignal-label-studio-server-side-request-forgery-in-url"},{"cve":"CVE-2026-22033","cvss":4,"epss":0.0028,"slug":"cve-2026-22033-label-studio-stored-xss-in-custom-hotkeys-with-account-takeover","title":"PYSEC-2026-1502 - Label Studio is vulnerable to full account takeover by chaining Stored XSS + IDOR in User Profile via custom_hotkeys field","severity":"medium","exploited":false,"published_at":"2026-07-07T16:03:18.065167+00:00","url":"https://junglewise.ai/threats/cve-2026-22033-label-studio-stored-xss-in-custom-hotkeys-with-account-takeover"},{"cve":"CVE-2025-25297","cvss":3.1,"epss":0.0067,"slug":"cve-2025-25297-label-studio-allows-server-side-request-forgery-in-the-s3-storage","title":"PYSEC-2026-1503 - Label Studio allows Server-Side Request Forgery in the S3 Storage Endpoint","severity":"low","exploited":false,"published_at":"2026-07-07T14:34:49.760107+00:00","url":"https://junglewise.ai/threats/cve-2025-25297-label-studio-allows-server-side-request-forgery-in-the-s3-storage"},{"cve":"CVE-2025-25296","cvss":3.1,"epss":0.019,"slug":"cve-2025-25296-label-studio-allows-cross-site-scripting-xss-via-get-request-to","title":"PYSEC-2026-1504 - Label Studio allows Cross-Site Scripting (XSS) via GET request to `/projects/upload-example` endpoint","severity":"low","exploited":false,"published_at":"2026-07-07T14:34:49.691604+00:00","url":"https://junglewise.ai/threats/cve-2025-25296-label-studio-allows-cross-site-scripting-xss-via-get-request-to"},{"cve":"CVE-2025-47783","cvss":4,"epss":0.0059,"slug":"cve-2025-47783-humansignal-label-studio-reflected-xss-in-label-config-parameter","title":"HumanSignal Label Studio reflected XSS in label_config parameter","severity":"high","exploited":false,"published_at":"2025-05-15T16:21:16+00:00","url":"https://junglewise.ai/threats/cve-2025-47783-humansignal-label-studio-reflected-xss-in-label-config-parameter"},{"cve":"CVE-2024-26152","cvss":3.1,"epss":0.0222,"slug":"cve-2024-26152-label-studio-vulnerable-to-cross-site-scripting-if-choices-or","title":"PYSEC-2024-249 - ### Summary\nOn all Label Studio versions prior to 1.11.0, data imported via file upload feature is not properly sanitized prior to being ren","severity":"low","exploited":false,"published_at":"2024-02-22T22:15:47+00:00","url":"https://junglewise.ai/threats/cve-2024-26152-label-studio-vulnerable-to-cross-site-scripting-if-choices-or"},{"cve":"CVE-2023-47116","cvss":3.1,"epss":0.0074,"slug":"cve-2023-47116-label-studio-ssrf-on-import-bypassing-ssrf-protection-enabled","title":"PYSEC-2024-127 - Label Studio is a popular open source data labeling tool. The vulnerability affects all versions of Label Studio prior to 1.11.0 and was tes","severity":"low","exploited":false,"published_at":"2024-01-31T17:15:00+00:00","url":"https://junglewise.ai/threats/cve-2023-47116-label-studio-ssrf-on-import-bypassing-ssrf-protection-enabled"},{"cve":"CVE-2024-23633","cvss":3.1,"epss":0.0059,"slug":"cve-2024-23633-cross-site-scripting-vulnerability-on-data-import","title":"PYSEC-2024-128 - Label Studio, an open source data labeling tool had a remote import feature allowed users to import data from a remote web source, that was","severity":"low","exploited":false,"published_at":"2024-01-24T00:15:00+00:00","url":"https://junglewise.ai/threats/cve-2024-23633-cross-site-scripting-vulnerability-on-data-import"},{"cve":"CVE-2023-47115","cvss":3.1,"epss":0.0145,"slug":"cve-2023-47115-cross-site-scripting-vulnerability-on-avatar-upload","title":"PYSEC-2024-126 - Label Studio is an a popular open source data labeling tool. Versions prior to 1.9.2 have a cross-site scripting (XSS) vulnerability that co","severity":"low","exploited":false,"published_at":"2024-01-23T23:15:00+00:00","url":"https://junglewise.ai/threats/cve-2023-47115-cross-site-scripting-vulnerability-on-avatar-upload"},{"cve":"CVE-2023-47117","cvss":3.1,"epss":0.0406,"slug":"cve-2023-47117-label-studio-object-relational-mapper-leak-vulnerability-in","title":"PYSEC-2023-275 - Label Studio is an open source data labeling tool. In all current versions of Label Studio prior to 1.9.2post0, the application allows users","severity":"low","exploited":false,"published_at":"2023-11-13T21:15:00+00:00","url":"https://junglewise.ai/threats/cve-2023-47117-label-studio-object-relational-mapper-leak-vulnerability-in"},{"cve":"CVE-2023-43791","cvss":3.1,"epss":0.0124,"slug":"cve-2023-43791-label-studio-has-hardcoded-django-secret-key-that-can-be-abused","title":"PYSEC-2023-274 - Label Studio is a multi-type data labeling and annotation tool with standardized output format. There is a vulnerability that can be chained","severity":"low","exploited":false,"published_at":"2023-11-09T15:15:00+00:00","url":"https://junglewise.ai/threats/cve-2023-43791-label-studio-has-hardcoded-django-secret-key-that-can-be-abused"},{"cvss":7.5,"slug":"label-studio-nginx-path-traversal-allows-unauthorized-file-access-08f7d110","title":"Label Studio Nginx path traversal allows unauthorized file access","severity":"high","exploited":false,"published_at":"2023-03-24T22:04:02+00:00","url":"https://junglewise.ai/threats/label-studio-nginx-path-traversal-allows-unauthorized-file-access-08f7d110"},{"cve":"CVE-2022-36551","cvss":3.1,"epss":0.0556,"slug":"cve-2022-36551-heartex-label-studio-community-edition-vulnerable-to-ssrf-in-the","title":"PYSEC-2022-300 - A Server Side Request Forgery (SSRF) in the Data Import module in Heartex - Label Studio Community Edition versions 1.5.0 and earlier allows","severity":"low","exploited":false,"published_at":"2022-10-03T12:15:00+00:00","url":"https://junglewise.ai/threats/cve-2022-36551-heartex-label-studio-community-edition-vulnerable-to-ssrf-in-the"}],"weekly":[{"week":"2026-06-29","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-06","critical":0,"exploited":0,"vulnerabilities":3},{"week":"2026-07-13","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-20","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-27","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-03","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-10","critical":0,"exploited":0,"vulnerabilities":1},{"week":"2026-08-17","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-24","critical":0,"exploited":0,"vulnerabilities":1},{"week":"2026-08-31","critical":0,"exploited":0,"vulnerabilities":2},{"week":"2026-09-07","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-14","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-21","critical":0,"exploited":0,"vulnerabilities":0}],"related":[{"name":"open-webui (PyPI)","slug":"open-webui","vulnerabilities":156,"url":"https://junglewise.ai/threats/technologies/open-webui"},{"name":"nltk (PyPI)","slug":"nltk","vulnerabilities":74,"url":"https://junglewise.ai/threats/technologies/nltk"},{"name":"picklescan (PyPI)","slug":"picklescan","vulnerabilities":74,"url":"https://junglewise.ai/threats/technologies/picklescan"},{"name":"openbabel (PyPI)","slug":"openbabel","vulnerabilities":48,"url":"https://junglewise.ai/threats/technologies/openbabel"},{"name":"apache-superset (PyPI)","slug":"apache-superset","vulnerabilities":44,"url":"https://junglewise.ai/threats/technologies/apache-superset"},{"name":"apache-airflow (PyPI)","slug":"apache-airflow","vulnerabilities":40,"url":"https://junglewise.ai/threats/technologies/apache-airflow"},{"name":"tensorflow-gpu (PyPI)","slug":"tensorflow-gpu","vulnerabilities":37,"url":"https://junglewise.ai/threats/technologies/tensorflow-gpu"},{"name":"tensorflow-cpu (PyPI)","slug":"tensorflow-cpu","vulnerabilities":34,"url":"https://junglewise.ai/threats/technologies/tensorflow-cpu"},{"name":"weblate (PyPI)","slug":"weblate","vulnerabilities":33,"url":"https://junglewise.ai/threats/technologies/weblate"},{"name":"mcp-atlassian (PyPI)","slug":"mcp-atlassian","vulnerabilities":30,"url":"https://junglewise.ai/threats/technologies/mcp-atlassian"},{"name":"crawl4ai (PyPI)","slug":"crawl4ai","vulnerabilities":28,"url":"https://junglewise.ai/threats/technologies/crawl4ai"},{"name":"moin (PyPI)","slug":"moin","vulnerabilities":28,"url":"https://junglewise.ai/threats/technologies/moin"}],"technology":{"hub":true,"name":"label-studio (PyPI)","slug":"label-studio","vendor":{"name":"PyPI","slug":"pypi","url":"https://junglewise.ai/threats/vendors/pypi"},"aliases":[],"homepage":"https://labelstud.io/","repo_url":"https://github.com/HumanSignal/label-studio","description":"An open-source data labeling tool for preparing training data for machine learning models.","url":"https://junglewise.ai/threats/technologies/label-studio"},"most_severe":[{"cve":"CVE-2026-76073","cvss":8.8,"epss":0.0052,"slug":"cve-2026-76073-label-studio-annotation-api-missing-organization-scope-check","title":"Label Studio annotation API missing organization scope check","severity":"high","exploited":false,"published_at":"2026-08-24T18:17:21.41+00:00","url":"https://junglewise.ai/threats/cve-2026-76073-label-studio-annotation-api-missing-organization-scope-check"},{"cve":"CVE-2026-85179","cvss":8.5,"epss":0.004,"slug":"cve-2026-85179-label-studio-webhook-url-validation-bypass","title":"Label Studio webhook URL validation bypass","severity":"high","exploited":false,"published_at":"2026-09-03T15:17:39.097+00:00","url":"https://junglewise.ai/threats/cve-2026-85179-label-studio-webhook-url-validation-bypass"},{"cve":"CVE-2026-85211","cvss":7.7,"epss":0.0042,"slug":"cve-2026-85211-label-studio-organization-filter-bypass-in-proxy-api-py","title":"Label Studio organization filter bypass in proxy_api.py","severity":"high","exploited":false,"published_at":"2026-09-03T15:17:40.257+00:00","url":"https://junglewise.ai/threats/cve-2026-85211-label-studio-organization-filter-bypass-in-proxy-api-py"},{"cvss":7.5,"slug":"label-studio-nginx-path-traversal-allows-unauthorized-file-access-08f7d110","title":"Label Studio Nginx path traversal allows unauthorized file access","severity":"high","exploited":false,"published_at":"2023-03-24T22:04:02+00:00","url":"https://junglewise.ai/threats/label-studio-nginx-path-traversal-allows-unauthorized-file-access-08f7d110"},{"cve":"CVE-2025-47783","cvss":4,"epss":0.0059,"slug":"cve-2025-47783-humansignal-label-studio-reflected-xss-in-label-config-parameter","title":"HumanSignal Label Studio reflected XSS in label_config parameter","severity":"high","exploited":false,"published_at":"2025-05-15T16:21:16+00:00","url":"https://junglewise.ai/threats/cve-2025-47783-humansignal-label-studio-reflected-xss-in-label-config-parameter"},{"cve":"CVE-2026-72560","cvss":6.5,"epss":0.0034,"slug":"cve-2026-72560-humansignal-label-studio-server-side-request-forgery-in-url","title":"HumanSignal Label Studio server-side request forgery in URL import","severity":"medium","exploited":false,"published_at":"2026-08-11T12:17:41.953+00:00","url":"https://junglewise.ai/threats/cve-2026-72560-humansignal-label-studio-server-side-request-forgery-in-url"},{"cve":"CVE-2026-22033","cvss":4,"epss":0.0028,"slug":"cve-2026-22033-label-studio-stored-xss-in-custom-hotkeys-with-account-takeover","title":"PYSEC-2026-1502 - Label Studio is vulnerable to full account takeover by chaining Stored XSS + IDOR in User Profile via custom_hotkeys field","severity":"medium","exploited":false,"published_at":"2026-07-07T16:03:18.065167+00:00","url":"https://junglewise.ai/threats/cve-2026-22033-label-studio-stored-xss-in-custom-hotkeys-with-account-takeover"},{"cve":"CVE-2022-36551","cvss":3.1,"epss":0.0556,"slug":"cve-2022-36551-heartex-label-studio-community-edition-vulnerable-to-ssrf-in-the","title":"PYSEC-2022-300 - A Server Side Request Forgery (SSRF) in the Data Import module in Heartex - Label Studio Community Edition versions 1.5.0 and earlier allows","severity":"low","exploited":false,"published_at":"2022-10-03T12:15:00+00:00","url":"https://junglewise.ai/threats/cve-2022-36551-heartex-label-studio-community-edition-vulnerable-to-ssrf-in-the"},{"cve":"CVE-2023-47117","cvss":3.1,"epss":0.0406,"slug":"cve-2023-47117-label-studio-object-relational-mapper-leak-vulnerability-in","title":"PYSEC-2023-275 - Label Studio is an open source data labeling tool. In all current versions of Label Studio prior to 1.9.2post0, the application allows users","severity":"low","exploited":false,"published_at":"2023-11-13T21:15:00+00:00","url":"https://junglewise.ai/threats/cve-2023-47117-label-studio-object-relational-mapper-leak-vulnerability-in"},{"cve":"CVE-2024-26152","cvss":3.1,"epss":0.0222,"slug":"cve-2024-26152-label-studio-vulnerable-to-cross-site-scripting-if-choices-or","title":"PYSEC-2024-249 - ### Summary\nOn all Label Studio versions prior to 1.11.0, data imported via file upload feature is not properly sanitized prior to being ren","severity":"low","exploited":false,"published_at":"2024-02-22T22:15:47+00:00","url":"https://junglewise.ai/threats/cve-2024-26152-label-studio-vulnerable-to-cross-site-scripting-if-choices-or"}],"generated_at":"2026-09-26T13:07:00.120236+00:00"}