Live data from GitHub and PyPI, updated daily.
Data last fetched: 2026-05-16
10 active CVEs reported via OSV.dev
Label Studio is vulnerable to full account takeover by chaining Stored XSS + IDOR in User Profile via custom_hotkeys field
Label Studio Object Relational Mapper Leak Vulnerability in Filtering Task
Label Studio vulnerable to Cross-site Scripting if `<Choices>` or `<Labels>` are used in labeling config
label-studio vulnerable to Cross-Site Scripting (Reflected) via the label_config parameter.
Nginx alias path traversal allows unauthenticated attackers to read all files on /label_studio/core/
Label Studio has Hardcoded Django `SECRET_KEY` that can be Abused to Forge Session Tokens
Cross-site Scripting Vulnerability on Data Import
Label Studio allows Server-Side Request Forgery in the S3 Storage Endpoint
Label Studio SSRF on Import Bypassing `SSRF_PROTECTION_ENABLED` Protections
Heartex - Label Studio Community Edition vulnerable to SSRF in the Data Import module
Get SLA-backed support, security patches, and direct access to senior engineers for Label Studio — without relying on volunteer maintainers.
Talk to an Expert →