label-studio-sdk@0.0.3 vulnerabilities

  • latest version

    1.0.10

  • latest non vulnerable version

  • first published

    3 years ago

  • latest version published

    18 days ago

  • licenses detected

  • Direct Vulnerabilities

    Known vulnerabilities in the label-studio-sdk package. This does not include vulnerabilities belonging to this package’s dependencies.

    How to fix?

    Automatically find and fix vulnerabilities affecting your projects. Snyk scans for vulnerabilities and provides fixes for free.

    Fix for free
    VulnerabilityVulnerable Version
    • H
    Directory Traversal

    Affected versions of this package are vulnerable to Directory Traversal via the download function due to improper input validation when processing image references during task exports.

    . An attacker can access files outside the intended directory structure by creating tasks with path traversal sequences in the image field during task exports in VOC, COCO, and YOLO formats.

    How to fix Directory Traversal?

    Upgrade label-studio-sdk to version 1.0.10 or higher.

    [,1.0.10)