CVE-2026-85179

Source
https://cve.org/CVERecord?id=CVE-2026-85179
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-85179.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-85179
Published
2026-09-03T14:12:18.328Z
Modified
2026-09-06T03:30:57.448845411Z
Severity
  • 8.4 (High) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:L/VA:N/SC:H/SI:L/SA:N CVSS Calculator
Summary
Label Studio through 1.23.0 SSRF via Unvalidated Webhook URL
Details

Label Studio through 1.23.0 fails to validate webhook URLs, allowing authenticated users to dispatch requests to internal services including RFC 1918 addresses and cloud metadata endpoints. Attackers can create webhooks targeting private networks and exfiltrate annotation data by enabling payload transmission in outbound requests.

Database specific
{
    "cwe_ids": [
        "CWE-918"
    ],
    "cna_assigner": "VulnCheck",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/85xxx/CVE-2026-85179.json"
}
References

Affected packages

Git / github.com/humansignal/label-studio

Affected ranges

Type
GIT
Repo
https://github.com/humansignal/label-studio
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Fixed
Database specific
Show details
{
    "source": [
        "DESCRIPTION",
        "REFERENCES"
    ],
    "extracted_events": [
        {
            "introduced": "0"
        },
        {
            "fixed": "1.23.0"
        }
    ]
}

Affected versions

Other
nightly
v.*
v.0.1.0
v.0.1.1
v.0.1.2
v.0.1.4
v.0.1.5
v.0.1.6
v.0.2.0
v.0.2.1-2
v.0.2.1-3
v.0.2.1-4
v.0.2.1-5
v.0.2.1-8
v0.*
v0.2.2
v0.3.0
v0.4.0
v0.4.4
v0.4.5
v0.4.6
v0.4.7
v0.4.8
v0.5.1
v0.6.0
v0.6.1
v0.7.0
v0.7.1
v0.7.2
v0.7.3
v0.7.5.post0
v0.8.0
v0.8.1
v0.8.2
v0.9.0
v0.9.0.post3
v0.9.0.post4
v0.9.0.post5
v0.9.1.post0
v0.9.1.post1
v1.*
v1.0.0
v1.0.1
v1.0.2
v1.1.0
v1.1.1
v1.2.0
v1.3.0
v1.4.0
v1.4.1

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-85179.json"