Label Studio versions before 1.18.0 can reflect label_config-derived content through the upload-example workflow [S1][S2]. GitHub and NVD track this as CVE-2025-47783 / GHSA-8jhr-wpcm-hh4h, with CWE-79 as the weakness class [S1][S2].
Impact
A malicious page can cause a user's browser to submit crafted data to the Label Studio origin. On affected deployments, the response can run script in that origin, which can expose data or trigger unauthorized browser-context actions [S1][S2]. GitHub notes that Label Studio session cookies are marked HttpOnly, which reduces direct session-cookie theft risk but does not remove the reflected XSS impact [S1].
Covered by FixVibe
FixVibe's verified active scans flag Label Studio deployments on your domain that show the vulnerable label_config upload-example behavior for CVE-2025-47783.
Remediation
Upgrade Label Studio to 1.18.0 or later and confirm the patched package or container image is what your deployment actually runs [S1][S2]. If an immediate upgrade is delayed, restrict Label Studio behind trusted access, make sure label_config-derived output is safely encoded, and serve generated examples with a safe response type. After patching, rerun a verified active FixVibe scan to confirm the exposure is gone.
