Server-Side Request Forgery Vulnerability in HumanSignal Label Studio
CVE-2026-72560

6.5MEDIUM

Key Information:

Vendor
CVE Published:
11 August 2026

What is CVE-2026-72560?

A server-side request forgery vulnerability exists in HumanSignal Label Studio due to the default setting of SSRF_PROTECTION_ENABLED being false. The vulnerability arises through the import-from-URL endpoint, which can be exploited by an authenticated user to send requests to any URL, including internal loopback addresses. This could allow access to internal services, cloud metadata endpoints, and other resources that are not intended for external access, posing a significant security risk.

Affected Version(s)

Label Studio 0 <= 1.24.0

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Bobur Abdugafforov
.