PT-2026-85045 · Unknown · Label Studio
CVSS v3.1
7.7
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Label Studio versions prior to 1.23.1
Description
Label Studio fails to apply organization filters when resolving storage URIs for tasks and projects within the
proxy api.py endpoints. This allows attackers to access cloud storage objects belonging to other tenants by creating a separate organization and providing arbitrary file URIs to presign or stream bucket contents.Recommendations
Update Label Studio to version 1.23.1 or later.
Exploit
Fix
IDOR
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Label Studio