VDB

CVE-2026-22033

CVE-2026-22033 PUBLISHED CVSS 8.600000381469727 HIGH

Label Studio is a multi-type data labeling and annotation tool. In 1.22.0 and earlier, a persistent stored cross-site scripting (XSS) vulnerability exists in the custom_hotkeys functionality of the application. An authenticated attacker (or one who can trick a user/administrator into updating their custom_hotkeys) can inject JavaScript code that executes in other users’ browsers when those users load any page using the templates/base.html template. Because the application exposes an API token endpoint (/api/current-user/token) to the browser and lacks robust CSRF protection on some API endpoints, the injected script may fetch the victim’s API token or call token reset endpoints — enabling full account takeover and unauthorized API access.

EPSS 0.01% · 2.8th percentile

Risk Scores

CVSS v4.0
8.600000381469727
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N
EPSS Score
0.01%
2.8th percentile

Affected Products

VendorProductVersions
HumanSignallabel-studio<= 1.22.0, <= 1.22.0
humansignallabel_studio0, 0
PyPIlabel-studio0, 0

Timeline

  • Dec 29, 2025 Fix PR Merged
  • Jan 12, 2026 CVE Published
  • Jan 12, 2026 PoC Published
  • Jan 13, 2026 EPSS Score
  • Jan 16, 2026 EPSS Score
  • Jan 19, 2026 EPSS Score
  • Jan 22, 2026 EPSS Score
  • Jan 24, 2026 PoC Published
  • Jan 25, 2026 EPSS Score
  • Jan 28, 2026 EPSS Score
  • Jan 30, 2026 Security Advisory
  • Jan 31, 2026 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›