label-studio@1.22.0 vulnerabilities

Label Studio annotation tool

Direct Vulnerabilities

Known vulnerabilities in the label-studio package. This does not include vulnerabilities belonging to this package’s dependencies.

Fix vulnerabilities automatically

Snyk's AI Trust Platform automatically finds the best upgrade path and integrates with your development workflows. Secure your code at zero cost.

Fix for free
VulnerabilityVulnerable Version
  • H
Cross-site Scripting (XSS)

label-studio is a Label Studio annotation tool

Affected versions of this package are vulnerable to Cross-site Scripting (XSS) via the custom_hotkeys process. An attacker can execute arbitrary JavaScript in the context of another user's browser and gain unauthorized access to sensitive API tokens by injecting malicious payloads into the custom_hotkeys field, which are then rendered unsafely in the application's HTML templates.

How to fix Cross-site Scripting (XSS)?

A fix was pushed into the master branch but not yet published.

[0,)