label-studio

Direct Vulnerabilities

Known vulnerabilities in the label-studio package. This does not include vulnerabilities belonging to this package’s dependencies.

Fix vulnerabilities automatically

Snyk's AI Trust Platform automatically finds the best upgrade path and integrates with your development workflows. Secure your code at zero cost.

Fix for free
VulnerabilityVulnerable Version
  • H
Loop with Unreachable Exit Condition ('Infinite Loop')

<1.23.1-r0
  • L
Resource Exhaustion

<1.23.1-r0
  • H
Inefficient Regular Expression Complexity

<1.23.1-r0
  • L
Cross-site Scripting (XSS)

<1.23.1-r0
  • L
Information Exposure

<1.23.1-r0
  • H
Untrusted Search Path

<1.23.1-r0
  • L
Arbitrary Code Injection

<1.23.1-r0
  • L
CVE-2026-12876

<1.23.1-r0
  • L
Uncontrolled Memory Allocation

<1.23.1-r0
  • L
Integer Overflow or Wraparound

<1.23.1-r0
  • L
Out-of-bounds Write

<1.23.1-r0
  • L
OS Command Injection

<1.23.1-r0
  • M
Improper Access Control

<1.23.1-r0
  • L
Resource Exhaustion

<1.23.1-r0
  • C
Deserialization of Untrusted Data

<1.23.1-r0
  • L
Resource Exhaustion

<1.23.1-r0
  • L
Resource Exhaustion

<1.23.1-r0
  • L
Directory Traversal

<1.23.1-r0
  • M
Integer Overflow or Wraparound

<1.23.1-r0
  • L
Information Exposure

<1.23.1-r0
  • L
Improper Cleanup on Thrown Exception

<1.23.1-r0
  • L
Uncontrolled Memory Allocation

<1.23.1-r0
  • L
Directory Traversal

<1.23.1-r0
  • H
Link Following

<1.23.1-r0
  • M
Improper Certificate Validation

<1.23.1-r0
  • L
Algorithmic Complexity

<1.23.1-r0
  • M
Link Following

<1.23.1-r0
  • L
Improper Input Validation

<1.23.1-r0
  • L
Resource Exhaustion

<1.23.1-r0
  • H
Insecure Default Initialization of Resource

<1.23.1-r0
  • H
Authorization Bypass Through User-Controlled Key

<1.23.1-r0
  • M
Server-Side Request Forgery (SSRF)

<1.23.1-r0
  • H
Allocation of Resources Without Limits or Throttling

<1.23.1-r0
  • L
Improper Certificate Validation

<1.23.1-r0
  • H
Uncontrolled Recursion

<1.23.1-r0
  • L
CVE-2026-12061

<1.23.1-r0
  • L
Improper Verification of Cryptographic Signature

<1.23.1-r0
  • L
Cross-site Scripting (XSS)

<1.23.1-r0
  • M
Loop with Unreachable Exit Condition ('Infinite Loop')

<1.23.1-r0
  • L
Unintended Proxy or Intermediary ('Confused Deputy')

<1.23.1-r0
  • L
Resource Exhaustion

<1.23.1-r0
  • H
External Control of File Name or Path

<1.23.1-r0
  • L
CVE-2026-53877

<1.23.1-r0
  • H
Server-Side Request Forgery (SSRF)

<1.23.1-r0
  • M
Insecure Temporary File

<1.23.1-r0
  • L
Arbitrary Code Injection

<1.23.1-r0
  • M
Inefficient Regular Expression Complexity

<1.23.1-r0
  • L
CVE-2026-12072

<1.23.1-r0
  • M
Directory Traversal

<1.23.1-r0
  • L
Out-of-bounds Read

<1.23.1-r0
  • M
Uncontrolled Recursion

<1.23.1-r0
  • L
Uncontrolled Memory Allocation

<1.23.1-r0
  • H
Directory Traversal

<1.23.1-r0
  • C
Deserialization of Untrusted Data

<1.23.1-r0
  • L
Resource Exhaustion

<1.23.1-r0
  • L
Arbitrary Code Injection

<1.23.1-r0
  • L
Improper Encoding or Escaping of Output

<1.23.1-r0
  • C
Arbitrary Argument Injection

<1.23.1-r0
  • L
Inefficient Regular Expression Complexity

<1.23.1-r0
  • L
Resource Exhaustion

<1.23.1-r0
  • H
Inefficient Regular Expression Complexity

<1.23.1-r0
  • L
CVE-2026-80206

<1.23.1-r0
  • L
Information Exposure

<1.23.1-r0
  • H
Authorization Bypass Through User-Controlled Key

<1.23.1-r0
  • L
GHSA-gj48-438w-jh9v

<1.23.1-r0
  • M
CVE-2026-13346

<1.23.1-r0
  • L
Allocation of Resources Without Limits or Throttling

<1.23.1-r0
  • C
Out-of-Bounds

<1.23.1-r0
  • M
CVE-2026-48587

<1.23.1-r0
  • H
Algorithmic Complexity

<1.23.1-r0
  • L
Improper Encoding or Escaping of Output

<1.23.1-r0
  • M
Heap-based Buffer Overflow

<1.23.1-r0
  • L
Server-Side Request Forgery (SSRF)

<1.23.1-r0
  • L
Arbitrary Code Injection

<1.23.1-r0
  • L
CVE-2026-12075

<1.23.1-r0
  • C
Out-of-bounds Read

<1.23.1-r0
  • L
Improper Certificate Validation

<1.23.1-r0
  • H
Improper Restriction of Recursive Entity References in DTDs ('XML Entity Expansion')

<1.23.1-r0
  • L
CVE-2026-53878

<1.23.1-r0
  • L
Arbitrary Code Injection

<1.23.1-r0
  • L
Integer Overflow or Wraparound

<1.23.1-r0
  • L
Resource Exhaustion

<1.23.1-r0
  • L
CVE-2026-48588

<1.23.1-r0
  • L
Algorithmic Complexity

<1.23.1-r0
  • L
CVE-2026-12074

<1.23.1-r0
  • H
External Control of File Name or Path

<1.23.1-r0
  • M
CVE-2026-6873

<1.23.1-r0
  • M
CVE-2026-8404

<1.23.1-r0
  • L
GHSA-8rfp-98v4-mmr6

<1.23.1-r0
  • L
Resource Exhaustion

<1.23.1-r0
  • L
Resource Exhaustion

<1.23.1-r0
  • L
Reliance on Reverse DNS Resolution for a Security-Critical Action

<1.23.1-r0
  • H
Server-Side Request Forgery (SSRF)

<1.23.1-r0
  • L
Server-Side Request Forgery (SSRF)

<1.23.1-r0
  • L
Uncontrolled Memory Allocation

<1.23.1-r0
  • L
GHSA-6v7p-g79w-8964

*
  • L
Insufficient Verification of Data Authenticity

<1.23.1-r0
  • L
Integer Overflow or Wraparound

<1.23.1-r0
  • L
XML External Entity (XXE) Injection

<1.23.1-r0
  • H
Resource Exhaustion

<1.23.1-r0
  • L
GHSA-537c-gmf6-5ccf

<1.23.1-r0
  • H
Memory Leak

<1.23.1-r0
  • L
Memory Leak

<1.23.1-r0
  • L
Directory Traversal

<1.23.1-r0
  • L
Improper Authentication

<1.23.1-r0
  • H
Directory Traversal

<1.23.1-r0
  • L
Missing Authentication for Critical Function

<1.23.1-r0
  • H
Integer Overflow or Wraparound

<1.23.1-r0
  • L
Uncontrolled Recursion

<1.23.1-r0