SSRF Vulnerability in Label Studio by HumanSignal
CVE-2026-85179

8.4HIGH

Key Information:

Vendor
CVE Published:
3 September 2026

What is CVE-2026-85179?

Label Studio versions prior to 1.23.0 suffer from a server-side request forgery (SSRF) vulnerability due to improper validation of webhook URLs. This security flaw allows authenticated users to send requests to internal services, including the potential to target private networks and access sensitive cloud metadata endpoints. As a result, attackers can exploit these unvalidated webhooks to exfiltrate annotation data by configuring malicious payloads for outbound requests. Organizations using affected versions should take immediate action to patch this vulnerability.

Affected Version(s)

label-studio 0 <= 1.23.0

References

CVSS V4

Score:
8.4
Severity:
HIGH
Confidentiality:
High
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

George Chen
.