label-studio is vulnerable to Cross-Site Scripting
50
Medium Risk
Affected versions of label-studio are vulnerable to Cross-site Scripting (XSS) when a label is converted to an SVG via the labelToSVG(...) function.
You are affected if you are use a vulnerable version of label-studio.
label-studio is vulnerable to Cross-Site Scripting in versions 1.12.0 - 1.12.0.post0 and 0.4.1 - 1.12.0.
Upgrade label-studio to a patch version (1.21.1).
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant