CVE-2025-25295 describes a path traversal vulnerability in Label Studio SDK versions prior to 1.0.10, affecting Label Studio versions before 1.16.0. This flaw allows an authenticated attacker to read arbitrary files from the server's filesystem by crafting tasks with malicious image paths during VOC, COCO, or YOLO project exports. The vulnerability has a high CVSS score of 8.7, indicating a significant risk of sensitive data exposure due to its network-based attack vector and low attack complexity. While no active exploitation, public exploit code, or significant community discussion has been observed, the potential for unauthorized file reads necessitates prompt patching.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| HumanSignal | Label-Studio | < 1.0.10CNA affected |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.