FixVibe

high

Reflected XSS in Label Studio via label_config Parameter

Label Studio versions before 1.18.0 have a reflected XSS issue in the label_config upload-example workflow. FixVibe verified active scans flag affected Label Studio deployments for CVE-2025-47783.

CVE-2025-47783GHSA-8jhr-wpcm-hh4hCWE-79

Label Studio versions before 1.18.0 can reflect label_config-derived content through the upload-example workflow [S1][S2]. GitHub and NVD track this as CVE-2025-47783 / GHSA-8jhr-wpcm-hh4h, with CWE-79 as the weakness class [S1][S2].

Impact

A malicious page can cause a user's browser to submit crafted data to the Label Studio origin. On affected deployments, the response can run script in that origin, which can expose data or trigger unauthorized browser-context actions [S1][S2]. GitHub notes that Label Studio session cookies are marked HttpOnly, which reduces direct session-cookie theft risk but does not remove the reflected XSS impact [S1].

Covered by FixVibe

FixVibe's verified active scans flag Label Studio deployments on your domain that show the vulnerable label_config upload-example behavior for CVE-2025-47783.

Remediation

Upgrade Label Studio to 1.18.0 or later and confirm the patched package or container image is what your deployment actually runs [S1][S2]. If an immediate upgrade is delayed, restrict Label Studio behind trusted access, make sure label_config-derived output is safely encoded, and serve generated examples with a safe response type. After patching, rerun a verified active FixVibe scan to confirm the exposure is gone.