OSS Support Hub / AI / ML

Python AI / ML

Label Studio

Open-source data labeling platform for machine learning

Project Health at a Glance

Live data from GitHub and PyPI, updated daily.

GitHub Stars
📦
Latest Release
🔄
Avg. Release Cadence
🐛
Open Issues
📅
Unknown
Last Commit
🔒
10
Active CVEs

Data last fetched: 2026-05-16

Known Vulnerabilities

10 active CVEs reported via OSV.dev

Label Studio is vulnerable to full account takeover by chaining Stored XSS + IDOR in User Profile via custom_hotkeys field

Published: 2026-01-12 No fix available

Label Studio Object Relational Mapper Leak Vulnerability in Filtering Task

Published: 2023-11-14 Fixed in: 1.9.2.post0

Label Studio vulnerable to Cross-site Scripting if `<Choices>` or `<Labels>` are used in labeling config

Published: 2024-02-22 Fixed in: 1.11.0

label-studio vulnerable to Cross-Site Scripting (Reflected) via the label_config parameter.

Published: 2025-05-15 Fixed in: 1.18.0

Nginx alias path traversal allows unauthenticated attackers to read all files on /label_studio/core/

Published: 2023-03-24 Fixed in: 1.7.2

Label Studio has Hardcoded Django `SECRET_KEY` that can be Abused to Forge Session Tokens

Published: 2023-11-09 Fixed in: 1.8.2

Cross-site Scripting Vulnerability on Data Import

Published: 2024-01-24 Fixed in: 1.10.1

Label Studio allows Server-Side Request Forgery in the S3 Storage Endpoint

Published: 2025-02-14 Fixed in: 1.16.0

Label Studio SSRF on Import Bypassing `SSRF_PROTECTION_ENABLED` Protections

Published: 2024-01-31 Fixed in: 1.11.0

Heartex - Label Studio Community Edition vulnerable to SSRF in the Data Import module

Published: 2022-10-04 Fixed in: 1.6.0

Alternatives to Label Studio

Other AI / ML projects in the Python ecosystem worth evaluating.

Support Options for Label Studio

Enterprise Support via DepKeep

Get SLA-backed support, security patches, and direct access to senior engineers for Label Studio — without relying on volunteer maintainers.

Talk to an Expert →

Community Channels