PT-2026-70135 · Humansignal · Label Studio

·

CVE-2026-72560

·

Published

2026-08-11

·

Updated

2026-08-11

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions HumanSignal Label Studio versions prior to 1.24.0.dev0
Description An authenticated user can perform a server-side request forgery (SSRF) because the SSRF PROTECTION ENABLED variable is set to false by default. This allows the 'import-from-URL' endpoint to fetch any caller-supplied URL, including internal loopback addresses, enabling access to internal services, cloud metadata endpoints, and other resources not intended for external access.
Recommendations Update HumanSignal Label Studio to a version later than 1.24.0.dev0. Set the SSRF PROTECTION ENABLED variable to true to enable protection.

Fix

SSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-72560

Affected Products

Label Studio