← Vulnerability feed

Vulnerability record · CVE-2023-43791 · published 9 November 2023

CVE-2023-43791: Humansignal label studio information exposure vulnerability

Humansignal · Label Studio

Label Studio is a multi-type data labeling and annotation tool with standardized output format. There is a vulnerability that can be chained within the ORM Leak vulnerability to impersonate any account on Label Studio. An attacker could exploit these vulnerabilities to escalate their privileges from a low privilege user to a Django Super Administrator user. The vulnerability was found to affect versions before `1.8.2`, where a patch was introduced.

8.8 CVSS 3.1 High EPSS 1.2% · top 32.0% CWE-200 · Information exposure
8.8CVSS 3.1 base score
1.2%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
8References, 2 tagged exploit
17 Jun 2026Last modified by NVD

Description

Label Studio is a multi-type data labeling and annotation tool with standardized output format. There is a vulnerability that can be chained within the ORM Leak vulnerability to impersonate any account on Label Studio. An attacker could exploit these vulnerabilities to escalate their privileges from a low privilege user to a Django Super Administrator user. The vulnerability was found to affect versions before `1.8.2`, where a patch was introduced.

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2023-43791 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

8.6CVE-2026-22033Humansignal label studio cross-site scripting vulnerabilityLabel Studio is a multi-type data labeling and annotation tool. In 1.22.0 and earlier, a persistent stored cross-site scripting (XSS) vulnerability e…EPSS 0.28%7.7CVE-2025-25297Humansignal label studio server-side request forgery (ssrf) vulnerabilityLabel Studio is an open source data labeling tool. Prior to version 1.16.0, Label Studio's S3 storage integration feature contains a Server-Side Requ…EPSS 0.67%7.6CVE-2025-47783Humansignal label studio cross-site scripting vulnerabilityLabel Studio is a multi-type data labeling and annotation tool. A vulnerability in versions prior to 1.18.0 allows an attacker to inject a malicious …EPSS 0.59%7.5CVE-2023-47117Humansignal label studio information exposure vulnerabilityLabel Studio is an open source data labeling tool. In all current versions of Label Studio prior to 1.9.2post0, the application allows users to insec…EPSS 4.1%6.1CVE-2025-25296Humansignal label studio cross-site scripting vulnerabilityLabel Studio is an open source data labeling tool. Prior to version 1.16.0, Label Studio's `/projects/upload-example` endpoint allows injection of ar…EPSS 1.9%6.1CVE-2024-26152Humansignal label studio cross-site scripting vulnerability### Summary On all Label Studio versions prior to 1.11.0, data imported via file upload feature is not properly sanitized prior to being rendered wit…EPSS 2.2%6.1CVE-2024-23633Humansignal label studio cross-site scripting vulnerabilityLabel Studio, an open source data labeling tool had a remote import feature allowed users to import data from a remote web source, that was downloade…EPSS 0.59%5.4CVE-2023-47115Humansignal label studio cross-site scripting vulnerabilityLabel Studio is an a popular open source data labeling tool. Versions prior to 1.9.2 have a cross-site scripting (XSS) vulnerability that could be ex…EPSS 1.4%

Source: NIST National Vulnerability Database (record CVE-2023-43791), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.