label-studio is vulnerable to Sensitive Information Exposure
20
Low Risk
Affected versions of this package may expose sensitive information by displaying full file paths in the UI when an import operation fails. This behavior has been corrected to show only the file name, helping users identify the failed file without revealing potentially sensitive path information.
You are affected if you are using a version that falls within the vulnerable range.
label-studio is vulnerable to Sensitive Information Exposure in versions 1.0.0 - 1.16.0.
Upgrade the label-studio library to the patch version.
Secure your code, cloud, and runtime environments in one central system. Find and fix vulnerabilities automatically.
No credit card required | Scan results in 32secs.
SOC 2Compliant
ISO 27001Compliant