Loading market data...
← Back to CVE feed

CVE-2026-85179

HIGH CVSS 8.5 View on NVD ↗

Description

Label Studio through 1.23.0 fails to validate webhook URLs, allowing authenticated users to dispatch requests to internal services including RFC 1918 addresses and cloud metadata endpoints. Attackers can create webhooks targeting private networks and exfiltrate annotation data by enabling payload transmission in outbound requests.

CVSS Vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:N
Published: Sep 03, 2026 15:17 UTC Modified: Sep 03, 2026 15:17 UTC