Deserialization Vulnerability in HumanSignal's Label Studio ML Backend
CVE-2025-5173

4.8MEDIUM

Key Information:

Vendor
CVE Published:
26 May 2025

What is CVE-2025-5173?

A deserialization vulnerability has been identified in HumanSignal's Label Studio ML Backend, specifically within the function load in the neural_nets.py file located at label-studio-ml-backend/label_studio_ml/examples/yolo/utils/. This flaw occurs when an attacker manipulates the argument path, leading to potential security risks. Currently, the issue must be approached locally, and the software uses a rolling release model, making it difficult to specify exact version details for affected releases. It is crucial for users to monitor updates and apply necessary patches to mitigate the risk associated with this vulnerability.

Affected Version(s)

label-studio-ml-backend 9fb7f4aa186612806af2becfb621f6ed8d9fdbaf

References

CVSS V4

Score:
4.8
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

ybdesire (VulDB User)
.