Cross-site Scripting Vulnerability on Avatar Upload
High7.1CVE-2023-47115 · Published Jan 24, 2024 · updated Sep 10, 2026
# Introduction This write-up describes a vulnerability found in [Label Studio](https://github.com/HumanSignal/label-studio), a popular open source data labeling tool. The vulnerability affects all versions of Label Studio prior to `1.9.2` and was tested on version `1.8.2`. # Overview [Label Studio](https://github.com/HumanSignal/label-studio) has a cross-site scripting (XSS) vulnerability that could be exploited when an authenticated user uploads a crafted image file for their avatar that gets rendered as a HTML file on the website. # Description The following [code snippet in Label Studio](https://github.com/HumanSignal/label-studio/blob/1.8.2/label_studio/users/functions.py#L18-L49) shows that the only verification check is that the file is an image by extracting the dimensions from the file. ```python def hash_upload(instance, filename): filename = str(uuid.uuid4())[0:8] + '-' + filename return settings.AVATAR_PATH + '/' + filename <3> def check_avatar(files): images = list(files.items()) if not images: return None filename, avatar = list(files.items())[0] # get first file w, h = get_image_dimensions(avatar) <1> if not w or not h: ...
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| label-studio PyPI | < 1.9.2 | 1.9.2 |
Details and references
# Introduction This write-up describes a vulnerability found in [Label Studio](https://github.com/HumanSignal/label-studio), a popular open source data labeling tool. The vulnerability affects all versions of Label Studio prior to `1.9.2` and was tested on version `1.8.2`. # Overview [Label Studio](https://github.com/HumanSignal/label-studio) has a cross-site scripting (XSS) vulnerability that could be exploited when an authenticated user uploads a crafted image file for their avatar that gets rendered as a HTML file on the website. # Description The following [code snippet in Label Studio](https://github.com/HumanSignal/label-studio/blob/1.8.2/label_studio/users/functions.py#L18-L49) shows that the only verification check is that the file is an image by extracting the dimensions from the file. ```python def hash_upload(instance, filename): filename = str(uuid.uuid4())[0:8] + '-' + filename return settings.AVATAR_PATH + '/' + filename <3> def check_avatar(files): images = list(files.items()) if not images: return None filename, avatar = list(files.items())[0] # get first file w, h = get_image_dimensions(avatar) <1> if not w or not h: raise forms.ValidationError("Can't read image, try another one") # validate dimensions max_width = max_height = 1200 if w > max_width or h > max_height: raise forms.ValidationError('Please use an image that is %s x %s pixels or smaller.' % (max_width, max_height)) # validate content type main, sub = avatar.content_type.split('/') <2> if not (main == 'image' and sub.lower() in ['jpeg', 'jpg', 'gif', 'png']): raise forms.ValidationError(u'Please use a JPEG, GIF or PNG image.') # validate file size max_size = 1024 * 1024 if len(avatar) > max_size: raise forms.ValidationError('Avatar file size may not exceed ' + str(max_size/1024) + ' kb') return avatar ``` 1. Attempts to get image dimensions to validate the uploaded avatar file is an image. 2. Extracts the `Content-Type` from the upload `POST` request. A user can easily bypass this verification by changing the mimetype of the uploaded file to an allowed type (eg. `image/jpeg`). 3. The file extension of the uploaded file is never validated and is saved to the filesystem. [Label Studio serves avatar images using Django's built-in `serve` view](https://github.com/HumanSignal/label-studio/blob/1.8.2/label_studio/users/urls.py#L25-L26), which is [not secure for production use according to Django's documentation](https://docs.djangoproject.com/en/4.2/ref/views/#serving-files-in-development). ```python re_path(r'^data/' + settings.AVATAR_PATH + '/(?P<path>.*)#x27;, serve, kwargs={'document_root': join(settings.MEDIA_ROOT, settings.AVATAR_PATH)}), ``` The issue with the Django `serve` view is that it determines the `Content-Type` of the response by the file extension in the URL path. Therefore, an attacker can upload an image that contains malicious HTML code and name the file with a `.html` extension to be rendered as a HTML page. The only file extension validation is performed on the client-side, which can be easily bypassed. # Proof of Concept Below are the steps to reproduce this issue and execute JavaScript code in the context of the Label Studio website. 1. Using any JPEG or PNG image, add in the comment field in the metadata the HTML code `<script>alert(document.domain)</script>`. This can be done using the `exiftool` command as shown below that was used to create the following image. ```bash exiftool -Comment='<script>alert(document.domain)</script>' penguin.jpg ```  2. On Label Studio, navigate to account & settings page and intercept the upload request of the avatar image using a tool such as Burp Suite. Modify the filename in the request to have a `.html
- CVSS 3.1
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L
- Severity from
- GitHub (reviewed advisory)
- Weakness
- CWE-79
- Also known as
- CVE-2023-47115, PYSEC-2024-126
- github.com/HumanSignal/label-studio/security/advisories/GHSA-q68h-xwq5-mm7x
- nvd.nist.gov/vuln/detail/CVE-2023-47115
- github.com/HumanSignal/label-studio/commit/a7a71e594f32ec4af8f3f800d5ccb8662e275da3
- docs.djangoproject.com/en/4.2/ref/views/#serving-files-in-development
- github.com/HumanSignal/label-studio
- github.com/HumanSignal/label-studio/blob/1.8.2/label_studio/users/functions.py#L18-L49
- github.com/HumanSignal/label-studio/blob/1.8.2/label_studio/users/urls.py#L25-L26
- github.com/pypa/advisory-database/tree/main/vulns/label-studio/PYSEC-2024-126.yaml
More Label Studio advisories
All Label Studio| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Feb 222024 | Label Studio vulnerable to Cross-site Scripting if `<Choices>` or `<Labels>` are used in labeling config | Medium4.7 | 1.11.0 |
| Jan 312024 | Label Studio SSRF on Import Bypassing `SSRF_PROTECTION_ENABLED` Protections | Medium5.3 | 1.11.0 |
| Jan 242024 | Cross-site Scripting Vulnerability on Data Import | Medium4.7 | 1.10.1 |
| Nov 142023 | Label Studio Object Relational Mapper Leak Vulnerability in Filtering Task | High7.5 | 1.9.2.post0 |
| Nov 92023 | Label Studio has Hardcoded Django `SECRET_KEY` that can be Abused to Forge Session Tokens | Critical9.8 | 1.8.2 |
| Mar 242023 | Nginx alias path traversal allows unauthenticated attackers to read all files on /label_studio/core/ | High7.5 | 1.7.2 |