CVE-2025-47783: label-studio vulnerable to Cross-Site Scripting (Reflected) via the label_config parameter.
(updated )
The vulnerability allows an attacker to inject a malicious script into the context of a web page, which can lead to data theft, unauthorized actions on behalf of the user, and other attacks.
References
- github.com/HumanSignal/label-studio/commit/97db9e7b16783e1f6052eb432a6f014f80ef268d
- github.com/HumanSignal/label-studio/security/advisories/GHSA-8jhr-wpcm-hh4h
- github.com/advisories/GHSA-8jhr-wpcm-hh4h
- github.com/pypa/advisory-database/tree/main/vulns/label-studio/PYSEC-2025-124.yaml
- nvd.nist.gov/vuln/detail/CVE-2025-47783
Code Behaviors & Features
Detect and mitigate CVE-2025-47783 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →