{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/cpes/cpe2.3aheartexlabel_studio/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:heartex:label_studio:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":7.7,"id":"CVE-2026-85211"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Label Studio"],"_cs_severities":["high"],"_cs_tags":["vulnerability","authorization-bypass","cloud","data-exfiltration"],"_cs_type":"advisory","_cs_vendors":["Heartex"],"content_html":"\u003cp\u003eLabel Studio, developed by Heartex, is vulnerable to an authorization bypass (CVE-2026-85211) within its storage management functionality. The flaw originates in the proxy_api.py module, where the application fails to properly enforce organization-level scoping when resolving storage URIs for tasks and projects.\u003c/p\u003e\n\u003cp\u003eDefenders should note that this vulnerability allows a malicious actor to circumvent multitenancy isolation. By creating a separate organization within a shared instance, an attacker can supply arbitrary file URIs to the system. The application then inadvertently allows the attacker to presign or stream bucket contents that they are not authorized to access. This leads to unauthorized data access and potential exfiltration of sensitive cloud storage objects across tenant boundaries. The vulnerability has a CVSS v3.1 base score of 7.7, reflecting the high impact on data confidentiality in multi-tenant cloud deployments.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows unauthorized users to access cloud storage assets belonging to other tenants. This compromises data isolation within multi-tenant Label Studio environments, potentially exposing sensitive datasets, project artifacts, or private cloud storage resources. The number of impacted organizations depends on the prevalence of multi-tenant, cloud-connected deployments of Label Studio.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003ePrioritized actions for security teams:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eVerify your Label Studio instance configuration for multi-tenancy and restrict public or cross-organization storage URI access until a vendor-supplied patch is applied.\u003c/li\u003e\n\u003cli\u003eReview access logs for proxy_api.py endpoints to identify anomalous requests targeting storage URIs that do not belong to the requesting user's organization.\u003c/li\u003e\n\u003cli\u003eMonitor for unauthorized cross-tenant data access patterns in cloud storage provider logs (e.g., S3, GCS) originating from the Label Studio server identity.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-03T15:22:24Z","date_published":"2026-09-03T15:22:24Z","id":"https://feed.craftedsignal.io/briefs/2026-09-label-studio-auth-bypass/","summary":"Label Studio contains an authorization bypass vulnerability in its proxy_api.py module that allows attackers to access and exfiltrate cloud storage objects belonging to other organizations.","title":"Authorization Bypass in Label Studio Storage URI Resolution","url":"https://feed.craftedsignal.io/briefs/2026-09-label-studio-auth-bypass/"}],"language":"en","title":"CraftedSignal Threat Feed - Cpe:2.3:a:heartex:label_studio:*:*:*:*:*:*:*:*","version":"https://jsonfeed.org/version/1.1"}