HumanSignal Vulnerabilities and Affected Products
Vulnerabilities associated with label_studio.
Products
Clear product- label-studio11 vulnerabilities
- Label Studio1 vulnerability
- label-studio-ml-backend1 vulnerability
- label_studio1 vulnerability
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2024-26152MEDIUM | Label Studio vulnerable to Cross-site Scripting if `<Choices>` or `<Labels>` are used in labeling config### Summary On all Label Studio versions prior to 1.11.0, data imported via file upload feature is not properly sanitized prior to being rendered within a [`Choices`](https://labelstud.io/tags/choices) or [`Labels`](https://labelstud.io/tags/labels) tag, resulting in an XSS vulnerability. ### Details Need permission to use the "data import" function. This was reproduced on Label Studio 1.10.1. ### PoC 1. Create a project. ![Create a project](https://github.com/HumanSignal/label-studio/assets/… CWE-79Feb 22, 2024 | CVSS4.7v3.1 | EPSS2.22% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |