← Vulnerability feed

Vulnerability record · CVE-2025-47783 · published 14 May 2025

CVE-2025-47783: Humansignal label studio cross-site scripting vulnerability

Humansignal · Label Studio

Label Studio is a multi-type data labeling and annotation tool. A vulnerability in versions prior to 1.18.0 allows an attacker to inject a malicious script into the context of a web page, which can lead to data theft, session hijacking, unauthorized actions on behalf of the user, and other attacks. The vulnerability is reproducible when sending a properly formatted request to the `POST /projects/upload-example/` endpoint. In the source code, the vulnerability is located at `label_studio/projects/views.py`. Version 1.18.0 contains a patch for the issue.

7.6 CVSS 4.0 High EPSS 0.59% · top 54.0% CWE-79 · Cross-site scripting
7.6CVSS 4.0 base score
0.59%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
1References, 1 tagged exploit
17 Jun 2026Last modified by NVD

Description

Label Studio is a multi-type data labeling and annotation tool. A vulnerability in versions prior to 1.18.0 allows an attacker to inject a malicious script into the context of a web page, which can lead to data theft, session hijacking, unauthorized actions on behalf of the user, and other attacks. The vulnerability is reproducible when sending a properly formatted request to the `POST /projects/upload-example/` endpoint. In the source code, the vulnerability is located at `label_studio/projects/views.py`. Version 1.18.0 contains a patch for the issue.

CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:H/VI:H/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2025-47783 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

8.8CVE-2023-43791Humansignal label studio information exposure vulnerabilityLabel Studio is a multi-type data labeling and annotation tool with standardized output format. There is a vulnerability that can be chained within t…EPSS 1.2%8.6CVE-2026-22033Humansignal label studio cross-site scripting vulnerabilityLabel Studio is a multi-type data labeling and annotation tool. In 1.22.0 and earlier, a persistent stored cross-site scripting (XSS) vulnerability e…EPSS 0.28%7.7CVE-2025-25297Humansignal label studio server-side request forgery (ssrf) vulnerabilityLabel Studio is an open source data labeling tool. Prior to version 1.16.0, Label Studio's S3 storage integration feature contains a Server-Side Requ…EPSS 0.67%7.5CVE-2023-47117Humansignal label studio information exposure vulnerabilityLabel Studio is an open source data labeling tool. In all current versions of Label Studio prior to 1.9.2post0, the application allows users to insec…EPSS 4.1%6.1CVE-2025-25296Humansignal label studio cross-site scripting vulnerabilityLabel Studio is an open source data labeling tool. Prior to version 1.16.0, Label Studio's `/projects/upload-example` endpoint allows injection of ar…EPSS 1.9%6.1CVE-2024-26152Humansignal label studio cross-site scripting vulnerability### Summary On all Label Studio versions prior to 1.11.0, data imported via file upload feature is not properly sanitized prior to being rendered wit…EPSS 2.2%6.1CVE-2024-23633Humansignal label studio cross-site scripting vulnerabilityLabel Studio, an open source data labeling tool had a remote import feature allowed users to import data from a remote web source, that was downloade…EPSS 0.59%5.4CVE-2023-47115Humansignal label studio cross-site scripting vulnerabilityLabel Studio is an a popular open source data labeling tool. Versions prior to 1.9.2 have a cross-site scripting (XSS) vulnerability that could be ex…EPSS 1.4%

Source: NIST National Vulnerability Database (record CVE-2025-47783), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.