Arbitrary File Upload Affecting label-studio package, versions [,1.8.0)
Do your applications use this vulnerable package?
In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applications- Snyk ID SNYK-PYTHON-LABELSTUDIO-6347239
- published 1 Mar 2024
- disclosed 1 Mar 2024
- credit Unknown
How to fix?
Upgrade label-studio
to version 1.8.0 or higher.
Overview
label-studio is a Label Studio annotation tool
Affected versions of this package are vulnerable to Arbitrary File Upload due to improper security checks. This could lead to malicious files being uploaded.
References
CVSS Scores
version 3.1