CVE-2026-85211: Humansignal Label-Studio
High severity, CVSS 7.7. EPSS: 0.4% chance of exploitation in the next 30 days.
Label Studio fails to apply organization filters when resolving storage URIs for tasks and projects in proxy_api.py endpoints. Attackers can access other tenants' cloud storage objects by creating a separate organization and supplying arbitrary file URIs to presign or stream bucket contents.
Affected products
- Humansignal Label-Studio: up to and including 1.23.0
Published 2026-09-03. Last modified 2026-09-10.