← Vulnerability feed

Vulnerability record · CVE-2026-22033 · published 12 January 2026

CVE-2026-22033: Humansignal label studio cross-site scripting vulnerability

Humansignal · Label Studio

Label Studio is a multi-type data labeling and annotation tool. In 1.22.0 and earlier, a persistent stored cross-site scripting (XSS) vulnerability exists in the custom_hotkeys functionality of the application. An authenticated attacker (or one who can trick a user/administrator into updating their custom_hotkeys) can inject JavaScript code that executes in other users’ browsers when those users load any page using the templates/base.html template. Because the application exposes an API token endpoint (/api/current-user/token) to the browser and lacks robust CSRF protection on some API endpoints, the injected script may fetch the victim’s API token or call token reset endpoints — enabling full account takeover and unauthorized API access.

8.6 CVSS 4.0 High EPSS 0.28% · top 81.3% CWE-79 · Cross-site scriptingCWE-284 · Improper access control
8.6CVSS 4.0 base score
0.28%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
3References, 1 tagged exploit
17 Jun 2026Last modified by NVD

Description

Label Studio is a multi-type data labeling and annotation tool. In 1.22.0 and earlier, a persistent stored cross-site scripting (XSS) vulnerability exists in the custom_hotkeys functionality of the application. An authenticated attacker (or one who can trick a user/administrator into updating their custom_hotkeys) can inject JavaScript code that executes in other users’ browsers when those users load any page using the templates/base.html template. Because the application exposes an API token endpoint (/api/current-user/token) to the browser and lacks robust CSRF protection on some API endpoints, the injected script may fetch the victim’s API token or call token reset endpoints — enabling full account takeover and unauthorized API access.

CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2026-22033 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

8.8CVE-2023-43791Humansignal label studio information exposure vulnerabilityLabel Studio is a multi-type data labeling and annotation tool with standardized output format. There is a vulnerability that can be chained within t…EPSS 1.2%7.7CVE-2025-25297Humansignal label studio server-side request forgery (ssrf) vulnerabilityLabel Studio is an open source data labeling tool. Prior to version 1.16.0, Label Studio's S3 storage integration feature contains a Server-Side Requ…EPSS 0.67%7.6CVE-2025-47783Humansignal label studio cross-site scripting vulnerabilityLabel Studio is a multi-type data labeling and annotation tool. A vulnerability in versions prior to 1.18.0 allows an attacker to inject a malicious …EPSS 0.59%7.5CVE-2023-47117Humansignal label studio information exposure vulnerabilityLabel Studio is an open source data labeling tool. In all current versions of Label Studio prior to 1.9.2post0, the application allows users to insec…EPSS 4.1%6.1CVE-2025-25296Humansignal label studio cross-site scripting vulnerabilityLabel Studio is an open source data labeling tool. Prior to version 1.16.0, Label Studio's `/projects/upload-example` endpoint allows injection of ar…EPSS 1.9%6.1CVE-2024-26152Humansignal label studio cross-site scripting vulnerability### Summary On all Label Studio versions prior to 1.11.0, data imported via file upload feature is not properly sanitized prior to being rendered wit…EPSS 2.2%6.1CVE-2024-23633Humansignal label studio cross-site scripting vulnerabilityLabel Studio, an open source data labeling tool had a remote import feature allowed users to import data from a remote web source, that was downloade…EPSS 0.59%5.4CVE-2023-47115Humansignal label studio cross-site scripting vulnerabilityLabel Studio is an a popular open source data labeling tool. Versions prior to 1.9.2 have a cross-site scripting (XSS) vulnerability that could be ex…EPSS 1.4%

Source: NIST National Vulnerability Database (record CVE-2026-22033), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.