id: PYSEC-2024-249 modified: 2025-05-19T11:22:35.312280Z published: 2024-02-22T22:15:47Z aliases: - CVE-2024-26152 - GHSA-6xv9-957j-qfhg details: | ### Summary On all Label Studio versions prior to 1.11.0, data imported via file upload feature is not properly sanitized prior to being rendered within a [`Choices`](https://labelstud.io/tags/choices) or [`Labels`](https://labelstud.io/tags/labels) tag, resulting in an XSS vulnerability. ### Details Need permission to use the "data import" function. This was reproduced on Label Studio 1.10.1. ### PoC 1. Create a project. ![Create a project](https://github.com/HumanSignal/label-studio/assets/3943358/9b1536ad-feac-4238-a1bd-ca9b1b798673) 2. Upload a file containing the payload using the "Upload Files" function. ![2 Upload a file containing the payload using the Upload Files function](https://github.com/HumanSignal/label-studio/assets/3943358/26bb7af1-1cd2-408f-9adf-61e31a5b7328) ![3 complete](https://github.com/HumanSignal/label-studio/assets/3943358/f2f62774-1fa6-4456-9e6f-8fa1ca0a2d2e) The following are the contents of the files used in the PoC ``` { "data": { "prompt": "labelstudio universe image", "images": [ { "value": "id123#0", "style": "margin: 5px", "html": "" } ] } } ``` 3. Select the text-to-image generation labeling template of Ranking and scoring ![3 Select the text-to-image generation labelling template for Ranking and scoring](https://github.com/HumanSignal/label-studio/assets/3943358/f227f49c-a718-4738-bc2a-807da4f97155) ![5 save](https://github.com/HumanSignal/label-studio/assets/3943358/9b529f8a-8e99-4bb0-bdf6-bb7a95c9b75d) 4. Select a task ![4 Select a task](https://github.com/HumanSignal/label-studio/assets/3943358/71856b7a-2b1f-44ea-99ab-fc48bc20caa7) 5. Check that the script is running ![5 Check that the script is running](https://github.com/HumanSignal/label-studio/assets/3943358/e396ae7b-a591-4db7-afe9-5bab30b48cb9) ### Impact Malicious scripts can be injected into the code, and when linked with vulnerabilities such as CSRF, it can cause even greater damage. In particular, It can become a source of further attacks, especially when linked to social engineering. affected: - package: ecosystem: PyPI name: label-studio purl: pkg:pypi/label-studio ranges: - type: GIT events: - introduced: "0" - fixed: 5df9ae3828b98652e9fa290a19f4deedf51ef6c8 repo: https://github.com/humansignal/label-studio - type: ECOSYSTEM events: - introduced: "0" - fixed: 1.11.0 versions: - 0.4.1 - 0.4.2 - 0.4.3 - 0.4.4 - 0.4.4.post1 - 0.4.4.post2 - 0.4.5 - 0.4.6 - 0.4.6.post1 - 0.4.6.post2 - 0.4.7 - 0.4.8 - 0.5.0 - 0.5.1 - 0.6.0 - 0.6.1 - 0.7.0 - 0.7.1 - 0.7.2 - 0.7.3 - 0.7.4 - 0.7.4.post0 - 0.7.4.post1 - 0.7.5.post1 - 0.7.5.post2 - 0.8.0 - 0.8.0.post0 - 0.8.1 - 0.8.1.post0 - 0.8.2 - 0.8.2.post0 - 0.9.0 - 0.9.0.post2 - 0.9.0.post3 - 0.9.0.post4 - 0.9.0.post5 - 0.9.1 - 0.9.1.post0 - 0.9.1.post1 - 0.9.1.post2 - 1.0.0 - 1.0.0.post0 - 1.0.0.post1 - 1.0.0.post2 - 1.0.0.post3 - 1.0.1 - 1.0.2 - 1.0.2.post0 - 1.1.0 - 1.1.0rc0 - 1.1.1 - 1.10.0 - 1.10.0.post0 - 1.10.1 - "1.2" - "1.3" - 1.3.post0 - 1.3.post1 - "1.4" - 1.4.1 - 1.4.1.post0 - 1.4.1.post1 - 1.5.0 - 1.5.0.post0 - 1.6.0 - 1.7.0 - 1.7.1 - 1.7.2 - 1.7.3 - 1.8.0 - 1.8.1 - 1.8.2 - 1.8.2.post0 - 1.8.2.post1 - 1.9.0 - 1.9.1 - 1.9.1.post0 - 1.9.2 - 1.9.2.post0 severity: - type: CVSS_V3 score: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N references: - type: ADVISORY url: https://github.com/HumanSignal/label-studio/security/advisories/GHSA-6xv9-957j-qfhg - type: EVIDENCE url: https://github.com/HumanSignal/label-studio/security/advisories/GHSA-6xv9-957j-qfhg - type: FIX url: https://github.com/HumanSignal/label-studio/commit/5df9ae3828b98652e9fa290a19f4deedf51ef6c8 - type: FIX url: https://github.com/HumanSignal/label-studio/pull/5232 - type: WEB url: https://github.com/HumanSignal/label-studio/releases/tag/1.11.0 - type: ADVISORY url: https://github.com/advisories/GHSA-6xv9-957j-qfhg