Humansignal develops data annotation and machine-learning labeling platforms, with its primary exposure centered on Label Studio and its associated ML backend component. The vendor's vulnerability profile reflects the attack surface of web-facing annotation services: cross-site scripting, sensitive information exposure, server-side request forgery, unsafe deserialization, and improper access control recur across its disclosures, indicating input-handling and authentication challenges typical of collaborative web applications. Current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Humansignal over time
Signals from CVEs in this vendor scope (11 CVEs).
11 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-47117HIGH Label Studio is an open source data labeling tool. In all current versions of Label Studio prior to 1.9.2post0, the application allows users to insecurely set filters for filtering | Nov 13, 2023 | 7.5 | 34 | NO | YES |
CVE-2025-25296MEDIUM Label Studio is an open source data labeling tool. Prior to version 1.16.0, Label Studio's `/projects/upload-example` endpoint allows injection of arbitrary HTML through a `GET` re | Feb 14, 2025 | 6.1 | 32 | NO | YES |
CVE-2025-47783MEDIUM Label Studio is a multi-type data labeling and annotation tool. A vulnerability in versions prior to 1.18.0 allows an attacker to inject a malicious script into the context of a we | May 14, 2025 | 6.1 | 28 | NO | YES |
CVE-2023-47115MEDIUM Label Studio is an a popular open source data labeling tool. Versions prior to 1.9.2 have a cross-site scripting (XSS) vulnerability that could be exploited when an authenticated u | Jan 23, 2024 | 5.4 | 27 | NO | YES |
CVE-2025-25297HIGH Label Studio is an open source data labeling tool. Prior to version 1.16.0, Label Studio's S3 storage integration feature contains a Server-Side Request Forgery (SSRF) vulnerabilit | Feb 14, 2025 | 7.7 | 23 | NO | NO |
CVE-2023-43791HIGH Label Studio is a multi-type data labeling and annotation tool with standardized output format. There is a vulnerability that can be chained within the ORM Leak vulnerability to im | Nov 9, 2023 | 8.8 | 22 | NO | NO |
CVE-2026-22033MEDIUM Label Studio is a multi-type data labeling and annotation tool. In 1.22.0 and earlier, a persistent stored cross-site scripting (XSS) vulnerability exists in the custom_hotkeys fun | Jan 12, 2026 | 5.4 | 21 | NO | NO |
CVE-2025-5173HIGH A vulnerability has been found in HumanSignal label-studio-ml-backend up to 9fb7f4aa186612806af2becfb621f6ed8d9fdbaf and classified as problematic. Affected by this vulnerability i | May 26, 2025 | 7.8 | 21 | NO | NO |
CVE-2024-26152MEDIUM ### Summary
On all Label Studio versions prior to 1.11.0, data imported via file upload feature is not properly sanitized prior to being rendered within a [`Choices`](https://label | Feb 22, 2024 | 6.1 | 18 | NO | NO |
CVE-2023-47116MEDIUM Label Studio is a popular open source data labeling tool. The vulnerability affects all versions of Label Studio prior to 1.11.0 and was tested on version 1.8.2. Label Studio's SSR | Jan 31, 2024 | 5.3 | 18 | NO | NO |
Signals from CVEs in this vendor scope (11 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Humansignal.
Media articles that mention a CVE ID that affects a product developed by Humansignal — matched by CVE ID, not by vendor name.