CPE
Label Studio versions up to 1.23.0 are vulnerable to Server-Side Request Forgery due to improper webhook URL validation, allowing authenticated attackers to target internal network services.