Server-Side Request Forgery Vulnerability in HumanSignal Label Studio
CVE-2026-72560
6.5MEDIUM
What is CVE-2026-72560?
A server-side request forgery vulnerability exists in HumanSignal Label Studio due to the default setting of SSRF_PROTECTION_ENABLED being false. The vulnerability arises through the import-from-URL endpoint, which can be exploited by an authenticated user to send requests to any URL, including internal loopback addresses. This could allow access to internal services, cloud metadata endpoints, and other resources that are not intended for external access, posing a significant security risk.
Affected Version(s)
Label Studio 0 <= 1.24.0
