Cross-Organization Storage URI Resolution Issue in Label Studio by HumanSignal
CVE-2026-85211

8.3HIGH

Key Information:

Vendor
CVE Published:
3 September 2026

What is CVE-2026-85211?

Label Studio has a security flaw where it fails to enforce organization filters during the processing of storage URIs via its proxy_api.py endpoints. This vulnerability enables attackers to manipulate the system by creating separate organizations and crafting arbitrary file URIs, thereby gaining unauthorized access to other tenants' cloud storage objects. This presents a significant risk as it could lead to data exposure and unauthorized access to sensitive information stored in the cloud.

Affected Version(s)

label-studio 0 <= 1.23.0

References

CVSS V4

Score:
8.3
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

George Chen
.