Stats Digest Feeds
โ† Back to all CVEs

CVE-2026-85211

HIGH NVD
CVSS Score 7.7
Severity HIGH
Published Sep 03, 2026
Vendor unknown

Description

Label Studio fails to apply organization filters when resolving storage URIs for tasks and projects in proxy_api.py endpoints. Attackers can access other tenants' cloud storage objects by creating a separate organization and supplying arbitrary file URIs to presign or stream bucket contents.

References