Label-studio

Latest version: v1.12.0.post0

Vulnerabilities (13)

CVE/PVE Vulnerability ID Advisory Affected versions Severity Severity Score
CVE-2023-47117 62286

Label-studio 1.9.2.post0 includes a fix for CVE-2023-47117: In all cu…

  • <1.9.2.post0
HIGH 7.5
CVE-2023-47115 64636

The vulnerability identified in Label Studio, a popular open-source d…

  • <1.92
MEDIUM 5.4
CVE-2023-43791 62254

Label-studio 1.8.2 includes a fix for CVE-2023-43791: There is a vuln…

  • <1.8.2
HIGH 8.8
PVE-2024-64704 64704

Label Studio version 1.8.0 introduces an extension check during file …

  • <1.8.0
- -
PVE-2023-99958 60895

Label-studio throughout 1.7.1 are vulnerable to path traversal via Ng…

  • <=1.7.1
- -
PVE-2024-64714 64714

Label-studio 1.5.0 includes a fix from OWASP security check. https:/…

  • <1.5.0
- -
CVE-2024-26152 66696

Label Studio before 1.11.0 is vulnerable to cross-site scripting (XSS…

  • <1.11.0
- -
CVE-2023-47116 64822

Label-studio 1.11.0 addresses the CVE-2023-47116 by introducing more …

  • <1.11.0
MEDIUM 5.3
PVE-2024-64709 64709

Label Studio 1.10.1 addresses the CVE-2024-2363. It could allow an at…

  • <1.10.1
- -
CVE-2024-23633 64643

Label Studio before 1.10.1 fixes a remote import feature that allows …

  • <1.10.1
MEDIUM 6.1
CVE-2022-36551 54502

A Server Side Request Forgery (SSRF) in the Data Import module in Hea…

  • >=0,<1.6.0
MEDIUM 6.5
PVE-2024-99780 66057

Label Studio before 0.9.1 is susceptible to an arbitrary code executi…

  • >=0,<0.9.1
- -
CVE-2021-34552 64706

Label-studio version 0.0.45 has updated its Pillow library dependency…

  • <0.0.45
CRITICAL 9.8