PyPi: Label-Studio

CVE-2024-26152

Safety vulnerability ID: 66696

This vulnerability was reviewed by experts

The information on this page was manually curated by our Cybersecurity Intelligence Team.

Created at Feb 22, 2024 Updated at Apr 07, 2025
Scan your Python projects for vulnerabilities →

Advisory

Label Studio before 1.11.0 is vulnerable to cross-site scripting (XSS) because it fails to properly sanitize data uploaded via the file upload feature before it is rendered within Choices or Labels tags. This vulnerability allows attackers to inject malicious scripts that could execute within the user's browser session. However, exploitation is contingent upon the attacker having permission to use the "data import" function.

Affected package

label-studio

Latest version: 1.17.0

Label Studio annotation tool

Affected versions

Fixed versions

Vulnerability changelog

This vulnerability has no description

Resources

Use this package?

Scan your Python project for dependency vulnerabilities in two minutes

Scan your application