CVE-2026-85211
Label Studio fails to apply organization filters when resolving storage URIs for tasks and projects in proxy_api.py endpoints. Attackers can access other tenants' cloud storage objects by creating a separate organization and supplying arbitrary file URIs to presign or stream bucket contents.
Слабость
Label Studio fails to apply organization filters when resolving storage URIs for tasks and projects in proxy_api.py endpoints. Attackers can access other tenants' cloud storage objects by creating a separate organization and supplying arbitrary file URIs to presign or stream bucket contents.
Источники
- https://github.com/HumanSignal/label-studio
- https://github.com/HumanSignal/label-studio/blob/1.23.0/label_studio/io_storages/proxy_api.py
- https://github.com/HumanSignal/label-studio/issues/9924
- https://www.vulncheck.com/advisories/label-studio-through-1.23.0-cross-organization-storage-uri-resolution
- https://github.com/HumanSignal/label-studio/issues/9924
Найдите уязвимость раньше атакующего.
Войдите через GitHub и запустите первый аудит меньше чем за минуту. Для бесплатного тарифа банковская карта не нужна.