Skip to content
Label StudioGHSA-pc6f-259w-w3j6

Heartex - Label Studio Community Edition vulnerable to SSRF in the Data Import module

High6.5CVE-2022-36551 · Published Oct 4, 2022 · updated Sep 27, 2024

A Server Side Request Forgery (SSRF) in the Data Import module in Heartex - Label Studio Community Edition versions 1.5.0 and earlier allows an authenticated user to access arbitrary files on the system. Furthermore, self-registration is enabled by default in these versions of Label Studio enabling a remote attacker to create a new account and then exploit the SSRF. This issue is fixed in version 1.6.0.

GitHub advisory

Affected versions

PackageAffectedFixed in
label-studio
PyPI
< 1.6.01.6.0
Details and references

More Label Studio advisories

All Label Studio

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.