Cross-Organization Storage URI Resolution Issue in Label Studio by HumanSignal
CVE-2026-85211
8.3HIGH
What is CVE-2026-85211?
Label Studio has a security flaw where it fails to enforce organization filters during the processing of storage URIs via its proxy_api.py endpoints. This vulnerability enables attackers to manipulate the system by creating separate organizations and crafting arbitrary file URIs, thereby gaining unauthorized access to other tenants' cloud storage objects. This presents a significant risk as it could lead to data exposure and unauthorized access to sensitive information stored in the cloud.
Affected Version(s)
label-studio 0 <= 1.23.0
