Intel

AIKIDO-2025-10220

label-studio is vulnerable to Sensitive Information Exposure

Sensitive Information Exposure Pre-CVE
Found by Aikido Intel before public disclosure or CVE publication.

20

Low Risk

This Affects:

PYTHONlabel-studio
1.0.0 - 1.16.0
Fixed in 1.17.0

TL;DR

Affected versions of this package may expose sensitive information by displaying full file paths in the UI when an import operation fails. This behavior has been corrected to show only the file name, helping users identify the failed file without revealing potentially sensitive path information.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

label-studio is vulnerable to Sensitive Information Exposure in versions 1.0.0 - 1.16.0.

How to fix this

Upgrade the label-studio library to the patch version.