SSRF Vulnerability in Label Studio by HumanSignal
CVE-2026-85179
8.4HIGH
What is CVE-2026-85179?
Label Studio versions prior to 1.23.0 suffer from a server-side request forgery (SSRF) vulnerability due to improper validation of webhook URLs. This security flaw allows authenticated users to send requests to internal services, including the potential to target private networks and access sensitive cloud metadata endpoints. As a result, attackers can exploit these unvalidated webhooks to exfiltrate annotation data by configuring malicious payloads for outbound requests. Organizations using affected versions should take immediate action to patch this vulnerability.
Affected Version(s)
label-studio 0 <= 1.23.0
