Intel

AIKIDO-2024-10121

label-studio is vulnerable to Cross-Site Scripting

Cross-Site Scripting Pre-CVE
Found by Aikido Intel before public disclosure or CVE publication.
Published Jun 4, 2024

50

Medium Risk

This Affects:

pythonlabel-studio
0.4.1 - 1.12.0
1.12.0 - 1.12.0.post0
Fixed in 1.12.1
Are you affected? Scan for Free

TL;DR

Affected versions of label-studio are vulnerable to Cross-site Scripting (XSS) when a label is converted to an SVG via the labelToSVG(...) function.

Who does this affect?

You are affected if you are use a vulnerable version of label-studio.

Background info

label-studio is vulnerable to Cross-Site Scripting in versions 1.12.0 - 1.12.0.post0 and 0.4.1 - 1.12.0.

How to fix this

Upgrade label-studio to a patch version (1.21.1).