LabKey Server is a research data-management and laboratory-information platform deployed in academic and biomedical environments, where its web interface presents a modest but notable attack surface. The platform's vulnerability profile clusters around web-layer input-handling and command-injection issues, including cross-site scripting, CSRF, command injection, and XML external entity processing weaknesses that are characteristic of complex data-entry and reporting interfaces. Public exploit code has been made available for some of these weaknesses, reflecting their appeal in research-infrastructure targeting; live severity and exploitation counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Labkey over time
Signals from CVEs in this vendor scope (6 CVEs).
6 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2019-9757HIGH An issue was discovered in LabKey Server 19.1.0. Sending an SVG containing an XXE payload to the endpoint visualization-exportImage.view or visualization-exportPDF.view allows loca | Oct 29, 2019 | 7.5 | 54 | NO | YES |
CVE-2019-3912MEDIUM An open redirect vulnerability in LabKey Server Community Edition before 18.3.0-61806.763 via the /__r1/ returnURL parameter allows an unauthenticated remote attacker to redirect u | Jan 30, 2019 | 6.1 | 33 | NO | YES |
CVE-2019-3911MEDIUM Reflected cross-site scripting (XSS) vulnerability in LabKey Server Community Edition before 18.3.0-61806.763 allows an unauthenticated remote attacker to inject arbitrary javascri | Jan 30, 2019 | 6.1 | 32 | NO | YES |
CVE-2019-9926HIGH An issue was discovered in LabKey Server 19.1.0. It is possible to force a logged-in administrator to execute code through a /reports-viewScriptReport.view CSRF vulnerability. | Oct 29, 2019 | 8.8 | 26 | NO | NO |
CVE-2019-3913MEDIUM Command manipulation in LabKey Server Community Edition before 18.3.0-61806.763 allows an authenticated remote attacker to unmount any drive on the system leading to denial of serv | Jan 30, 2019 | 4.9 | 19 | NO | NO |
CVE-2019-9758MEDIUM An issue was discovered in LabKey Server 19.1.0. The display name of a user is vulnerable to stored XSS that can execute on administrators from security/permissions.view, security/ | Oct 29, 2019 | 5.4 | 16 | NO | NO |
Signals from CVEs in this vendor scope (6 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Labkey.
Media articles that mention a CVE ID that affects a product developed by Labkey — matched by CVE ID, not by vendor name.