Safety vulnerability ID: 54502
The information on this page was manually curated by our Cybersecurity Intelligence Team.
A Server Side Request Forgery (SSRF) in the Data Import module in Heartex - Label Studio Community Edition versions 1.5.0 and earlier allows an authenticated user to access arbitrary files on the system. Furthermore, self-registration is enabled by default in these versions of Label Studio enabling a remote attacker to create a new account and then exploit the SSRF. This issue is fixed in version 1.6.0.
Latest version: 1.17.0
Label Studio annotation tool
This vulnerability has no description
Scan your Python project for dependency vulnerabilities in two minutes
Scan your application