CVE-2026-85179

Label Studio through 1.23.0 fails to validate webhook URLs, allowing authenticated users to dispatch requests to internal services including RFC 1918 addresses and cloud metadata endpoints. Attackers can create webhooks targeting private networks and exfiltrate annotation data by enabling payload transmission in outbound requests.
Configurations

No configuration.

History

No history.

Information

Published : 2026-09-03 15:17

Updated : 2026-09-05 02:17


NVD link : CVE-2026-85179

Mitre link : CVE-2026-85179

CVE.ORG link : CVE-2026-85179


JSON object : View

Products Affected

No product.

CWE
CWE-918

Server-Side Request Forgery (SSRF)