CVE-2026-85211 UNKNOWN

CVE-2026-85211

Published: 2026-09-03

Description

Label Studio fails to apply organization filters when resolving storage URIs for tasks and projects in proxy_api.py endpoints. Attackers can access other tenants' cloud storage objects by creating a separate organization and supplying arbitrary file URIs to presign or stream bucket contents.

AI Intelligence Brief

AI Intelligence

Analyzing vulnerability vectors…