<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Cpe:2.3:a:labelstudio:label_studio:*:*:*:*:*:*:*:* - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/cpes/cpe2.3alabelstudiolabel_studio/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Thu, 03 Sep 2026 15:22:01 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/cpes/cpe2.3alabelstudiolabel_studio/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Label Studio SSRF via Webhook URL Validation Bypass</title><link>https://feed.craftedsignal.io/briefs/2026-09-label-studio-ssrf/</link><pubDate>Thu, 03 Sep 2026 15:22:01 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-09-label-studio-ssrf/</guid><description>Label Studio versions up to 1.23.0 are vulnerable to Server-Side Request Forgery due to improper webhook URL validation, allowing authenticated attackers to target internal network services.</description><content:encoded><![CDATA[<p>Label Studio versions through 1.23.0 contain a Server-Side Request Forgery (SSRF) vulnerability due to insufficient validation of webhook URLs. This vulnerability allows an authenticated user to craft malicious webhook requests that reach internal network resources, including those residing on RFC 1918 address spaces and cloud instance metadata services (e.g., 169.254.169.254).</p>
<p>By manipulating the webhook configuration, an attacker can force the Label Studio server to perform outbound requests on their behalf. This can be weaponized to interact with internal APIs that lack authentication or to exfiltrate sensitive environment configuration data and annotation datasets. The impact is significant for organizations hosting Label Studio within sensitive internal network segments or cloud environments where internal service discovery relies on metadata endpoints.</p>
<h2 id="impact">Impact</h2>
<p>Successful exploitation allows authenticated attackers to bypass network perimeters, potentially leading to unauthorized data exfiltration of sensitive annotations, reconnaissance of internal network infrastructure, and compromise of internal services accessible from the Label Studio host.</p>
<h2 id="recommendation">Recommendation</h2>
<p>Prioritize the identification and patching of Label Studio instances running version 1.23.0 or earlier. Audit current webhook configurations to identify any entries pointing to internal IP addresses or private domain namespaces.</p>
]]></content:encoded><category domain="severity">high</category><category domain="type">advisory</category><category>ssrf</category><category>web-application</category><category>data-exfiltration</category></item></channel></rss>