Path Traversal Vulnerability in Label Studio SDK by HumanSignal
CVE-2025-25295

8.7HIGH

Key Information:

Vendor
CVE Published:
14 February 2025

What is CVE-2025-25295?

Label Studio is an open-source data labeling tool that is vulnerable to a path traversal issue in its SDK. This flaw, present in versions prior to 1.0.10, can lead to unauthorized file access outside the intended directory structure. Specifically, functionalities that export tasks in VOC, COCO, and YOLO formats invoke a download method from the label-studio-sdk Python package, which inadequately verifies file paths when processing image references. By exploiting this flaw with crafted tasks containing path traversal sequences, an attacker may read arbitrary files from the server's filesystem. This vulnerability necessitates authentication, and its exploitation could expose sensitive information like configuration files, credentials, and other confidential data. Users are advised to upgrade to Label Studio version 1.16.0 or later to mitigate the risks associated with this vulnerability.

Affected Version(s)

label-studio < 1.0.10

References

CVSS V4

Score:
8.7
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.