label-studio@1.12.1 vulnerabilities

Label Studio annotation tool

  • latest version

    1.17.0

  • latest non vulnerable version

  • first published

    5 years ago

  • latest version published

    12 days ago

  • licenses detected

  • Direct Vulnerabilities

    Known vulnerabilities in the label-studio package. This does not include vulnerabilities belonging to this package’s dependencies.

    How to fix?

    Automatically find and fix vulnerabilities affecting your projects. Snyk scans for vulnerabilities and provides fixes for free.

    Fix for free
    VulnerabilityVulnerable Version
    • H
    Directory Traversal

    label-studio is a Label Studio annotation tool

    Affected versions of this package are vulnerable to Directory Traversal via the download function due to improper input validation when processing image references during task exports.

    . An attacker can access files outside the intended directory structure by creating tasks with path traversal sequences in the image field during task exports in VOC, COCO, and YOLO formats.

    How to fix Directory Traversal?

    Upgrade label-studio to version 1.16.0 or higher.

    [,1.16.0)
    • M
    Cross-site Scripting (XSS)

    label-studio is a Label Studio annotation tool

    Affected versions of this package are vulnerable to Cross-site Scripting (XSS) through the /projects/upload-example endpoint due to improper sanitization of the input passed to the label_config query parameter.

    How to fix Cross-site Scripting (XSS)?

    Upgrade label-studio to version 1.16.0 or higher.

    [,1.16.0)
    • M
    Server-side Request Forgery (SSRF)

    label-studio is a Label Studio annotation tool

    Affected versions of this package are vulnerable to Server-side Request Forgery (SSRF) via the s3_endpoint parameter due to improper input validation. An attacker can make the application send HTTP requests to arbitrary internal services by specifying them as the S3 endpoint.

    How to fix Server-side Request Forgery (SSRF)?

    Upgrade label-studio to version 1.16.0 or higher.

    [,1.16.0)