Security Advisory
CVE-2026-85211
CVE vulnerability detail - eXtreme Datacenter Security Operations
Description
Label Studio fails to apply organization filters when resolving storage URIs for tasks and projects in proxy_api.py endpoints. Attackers can access other tenants' cloud storage objects by creating a separate organization and supplying arbitrary file URIs to presign or stream bucket contents.