CVE-2025-25296
CVSS 3.1 Score 6.1 of 10 (medium)
Details
Summary
CVE-2025-25296 is a vulnerability affecting Label Studio, an open-source data labeling tool, prior to version 1.16.0. The vulnerability allows for Cross-Site Scripting (XSS) attacks through the `/projects/upload-example` endpoint. By crafting a specifically formatted XML label config with inline task data containing malicious HTML/JavaScript, attackers can inject and execute arbitrary scripts in victims' browsers. The application's Content Security Policy (CSP) only functions in report-only mode, rendering it ineffective against script execution. The vulnerability arises due to the endpoint rendering user-provided HTML content without proper sanitization on a GET request. This exposure can lead to data theft, session hijacking, and other malicious actions. Version 1.16.0 includes a patch to address this issue.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.