Security Advisory

CVE-2026-85211

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2026-09-03 14:12:22
Last updated 2026-09-03 14:37:19
Assigner VulnCheck
CVSS score 8.3
State PUBLISHED

Description

Label Studio fails to apply organization filters when resolving storage URIs for tasks and projects in proxy_api.py endpoints. Attackers can access other tenants' cloud storage objects by creating a separate organization and supplying arbitrary file URIs to presign or stream bucket contents.