Showing 1 vulnerability on this page for label_studio

Signals CISA KEV Ransomware Nuclei
HumanSignal vulnerability results
VulnerabilityTitle and contextCVSSEPSSPoCsSignalsSTIX action

Label Studio vulnerable to Cross-site Scripting if `<Choices>` or `<Labels>` are used in labeling config

### Summary On all Label Studio versions prior to 1.11.0, data imported via file upload feature is not properly sanitized prior to being rendered within a [`Choices`](https://labelstud.io/tags/choices) or [`Labels`](https://labelstud.io/tags/labels) tag, resulting in an XSS vulnerability. ### Details Need permission to use the "data import" function. This was reproduced on Label Studio 1.10.1. ### PoC 1. Create a project. ![Create a project](https://github.com/HumanSignal/label-studio/assets/

CWE-79Feb 22, 2024
CVSS4.7v3.1EPSS2.22%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX