CVE-2025-25295 - CVE House
Back to Database
Status published High CVE-2025-25295

Label Studio has a Path Traversal Vulnerability via image Field

Vulnerability Description

Label Studio is an open source data labeling tool. A path traversal vulnerability in Label Studio SDK versions prior to 1.0.10 allows unauthorized file access outside the intended directory structure. The flaw exists in the VOC, COCO and YOLO export functionalities. These functions invoke a `download` function on the `label-studio-sdk` python package, which fails to validate file paths when processing image references during task exports. By creating tasks with path traversal sequences in the image field, an attacker can force the application to read files from arbitrary server filesystem locations when exporting projects in any of the mentioned formats. This is authentication-required vulnerability allowing arbitrary file reads from the server filesystem. It may lead to potential exposure of sensitive information like configuration files, credentials, and confidential data. Label Studio versions before 1.16.0 specified SDK versions prior to 1.0.10 as dependencies, and the issue was confirmed in Label Studio version 1.13.2.dev0; therefore, Label Studio users should upgrade to 1.16.0 or newer to mitigate it.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-25295

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

HumanSignal

View all reports →

Affected Software

label-studio
Vulnerable Versions:
< 1.0.10

Timeline

Official Publish: February 14th, 2025
Last Modified: March 3rd, 2025
Added to House: July 22nd, 2026

CVSS Vectors

Weaknesses (CWE)