Safety vulnerability ID: 66696
The information on this page was manually curated by our Cybersecurity Intelligence Team.
Label Studio before 1.11.0 is vulnerable to cross-site scripting (XSS) because it fails to properly sanitize data uploaded via the file upload feature before it is rendered within Choices or Labels tags. This vulnerability allows attackers to inject malicious scripts that could execute within the user's browser session. However, exploitation is contingent upon the attacker having permission to use the "data import" function.
Latest version: 1.17.0
Label Studio annotation tool
This vulnerability has no description
Scan your Python project for dependency vulnerabilities in two minutes
Scan your application