PyPi: Label-Studio

CVE-2023-43791

Safety vulnerability ID: 62254

This vulnerability was reviewed by experts

The information on this page was manually curated by our Cybersecurity Intelligence Team.

Created at Nov 09, 2023 Updated at Apr 07, 2025
Scan your Python projects for vulnerabilities →

Advisory

Label-studio 1.8.2 includes a fix for CVE-2023-43791: There is a vulnerability that can be chained within the ORM Leak vulnerability to impersonate any account on Label Studio. An attacker could exploit these vulnerabilities to escalate their privileges from a low privilege user to a Django Super Administrator user.
https://github.com/HumanSignal/label-studio/security/advisories/GHSA-f475-x83m-rx5m

Affected package

label-studio

Latest version: 1.17.0

Label Studio annotation tool

Affected versions

Fixed versions

Vulnerability changelog

Label Studio is a multi-type data labeling and annotation tool with standardized output format. There is a vulnerability that can be chained within the ORM Leak vulnerability to impersonate any account on Label Studio. An attacker could exploit these vulnerabilities to escalate their privileges from a low privilege user to a Django Super Administrator user. The vulnerability was found to affect versions before `1.8.2`, where a patch was introduced. See CVE-2023-43791.


MISC:https://github.com/HumanSignal/label-studio/commit/3d06c5131c15600621e08b06f07d976887cde81b: https://github.com/HumanSignal/label-studio/commit/3d06c5131c15600621e08b06f07d976887cde81b
MISC:https://github.com/HumanSignal/label-studio/pull/4690: https://github.com/HumanSignal/label-studio/pull/4690
MISC:https://github.com/HumanSignal/label-studio/releases/tag/1.8.2: https://github.com/HumanSignal/label-studio/releases/tag/1.8.2
MISC:https://github.com/HumanSignal/label-studio/security/advisories/GHSA-f475-x83m-rx5m: https://github.com/HumanSignal/label-studio/security/advisories/GHSA-f475-x83m-rx5m

Resources

Use this package?

Scan your Python project for dependency vulnerabilities in two minutes

Scan your application

Severity Details

CVSS Base Score

HIGH 8.8

CVSS v3 Details

HIGH 8.8
Attack Vector (AV)
NETWORK
Attack Complexity (AC)
LOW
Privileges Required (PR)
LOW
User Interaction (UI)
NONE
Scope (S)
UNCHANGED
Confidentiality Impact (C)
HIGH
Integrity Impact (I)
HIGH
Availability Availability (A)
HIGH