CVE-2026-85211
Label Studio fails to apply organization filters when resolving storage URIs for tasks and projects in proxy_api.py endpoints. Attackers can access other tenants' cloud storage objects by creating a separate organization and supplying arbitrary file URIs to presign or stream bucket contents.
نوع الضعف
Label Studio fails to apply organization filters when resolving storage URIs for tasks and projects in proxy_api.py endpoints. Attackers can access other tenants' cloud storage objects by creating a separate organization and supplying arbitrary file URIs to presign or stream bucket contents.
المراجع
- https://github.com/HumanSignal/label-studio
- https://github.com/HumanSignal/label-studio/blob/1.23.0/label_studio/io_storages/proxy_api.py
- https://github.com/HumanSignal/label-studio/issues/9924
- https://www.vulncheck.com/advisories/label-studio-through-1.23.0-cross-organization-storage-uri-resolution
- https://github.com/HumanSignal/label-studio/issues/9924
اكتشف الثغرة قبل أن يكتشفها المهاجم.
سجّل الدخول عبر GitHub وشغّل أول تدقيق لك في أقل من دقيقة. الخطة المجانية لا تتطلب بطاقة ائتمان.