Label Studio through 1.23.0 Cross-Organization Storage URI Resolution
21Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackcvss 8.3epss 0.2%
exploitation probability
0.2%top 85% of all CVEs
observed exploitation
nono source reports it
Label Studio fails to apply organization filters when resolving storage URIs for tasks and projects in proxy_api.py endpoints. Attackers can access other tenants' cloud storage objects by creating a separate organization and supplying arbitrary file URIs to presign or stream bucket contents.
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N
Affected products
HumanSignal · label-studioReferences
https://github.com/HumanSignal/label-studiohttps://github.com/HumanSignal/label-studio/blob/1.23.0/label_studio/io_storages/proxy_api.pyhttps://github.com/HumanSignal/label-studio/issues/9924https://www.vulncheck.com/advisories/label-studio-through-1.23.0-cross-organization-storage-uri-resolution