CVE-2026-85211: Humansignal Label-Studio

High severity, CVSS 7.7. EPSS: 0.4% chance of exploitation in the next 30 days.

Label Studio fails to apply organization filters when resolving storage URIs for tasks and projects in proxy_api.py endpoints. Attackers can access other tenants' cloud storage objects by creating a separate organization and supplying arbitrary file URIs to presign or stream bucket contents.

Affected products

Published 2026-09-03. Last modified 2026-09-10.