GHSA-q68h-xwq5-mm7x is a high-severity (CVSS 7.1) Cross-site Scripting (XSS) vulnerability in label-studio. 1 public exploit reference exists, so weaponization risk is real. A fix is available for label-studio — see the affected versions and patch details below.
Cross-site Scripting Vulnerability on Avatar Upload
Exploitation Status
Proof-of-concept exploit code exists
- CISA’s SSVC triage found public proof-of-concept exploit code for this CVE, though no confirmed active exploitation.
Exploitation and automatability from CISA’s SSVC triage for GHSA-q68h-xwq5-mm7x.
EPSS Exploitation Probability
EPSS (Exploit Prediction Scoring System) is a daily probability model maintained by FIRST.org. It estimates the likelihood a CVE will be exploited in production environments within the next 30 days, derived from real-world threat intelligence signals.
How urgent is this, really
GHSA-q68h-xwq5-mm7x plotted by exploitation likelihood (EPSS) against impact (CVSS). The shaded corner — EPSS 50%+ and CVSS 7.0+ — is where this CVE doesn't sit, though severity or exploitability alone can still warrant action.
Where this sits among everything scored
Of 378,156 CVEs with a current EPSS score, this one falls in the < 10% band (highlighted). Real counts from FIRST.org, not a sample — log-scaled since the landscape is heavily right-skewed.
Real-World Exposure
label-studioReal-time download stats are indexed for npm and PyPI packages. This vulnerability affects PyPI packages — download data is not available via public APIs for these ecosystems.
Description
Introduction
This write-up describes a vulnerability found in Label Studio, a popular open source data labeling tool. The vulnerability affects all versions of Label Studio prior to 1.9.2 and was tested on version 1.8.2.
Overview
Label Studio has a cross-site scripting (XSS) vulnerability that could be exploited when an authenticated user uploads a crafted image file for their avatar that gets rendered as a HTML file on the website.
Description
The following code snippet in Label Studio shows that the only verification check is that the file is an image by extracting the dimensions from the file.
def hash_upload(instance, filename):
filename = str(uuid.uuid4())[0:8] + '-' + filename
return settings.AVATAR_PATH + '/' + filename <3>
def check_avatar(files):
images = list(files.items())
if not images:
return None
filename, avatar = list(files.items())[0] # get first file
w, h = get_image_dimensions(avatar) <1>
if not w or not h:
raise forms.ValidationError("Can't read image, try another one")
# validate dimensions
max_width = max_height = 1200
if w > max_width or h > max_height:
raise forms.ValidationError('Please use an image that is %s x %s pixels or smaller.'
% (max_width, max_height))
# validate content type
main, sub = avatar.content_type.split('/') <2>
if not (main == 'image' and sub.lower() in ['jpeg', 'jpg', 'gif', 'png']):
raise forms.ValidationError(u'Please use a JPEG, GIF or PNG image.')
# validate file size
max_size = 1024 * 1024
if len(avatar) > max_size:
raise forms.ValidationError('Avatar file size may not exceed ' + str(max_size/1024) + ' kb')
return avatar
- Attempts to get image dimensions to validate the uploaded avatar file is an image.
- Extracts the
Content-Typefrom the uploadPOSTrequest. A user can easily bypass this verification by changing the mimetype of the uploaded file to an allowed type (eg.image/jpeg). - The file extension of the uploaded file is never validated and is saved to the filesystem.
Label Studio serves avatar images using Django's built-in serve view, which is not secure for production use according to Django's documentation.
re_path(r'^data/' + settings.AVATAR_PATH + '/(?P<path>.*)$', serve,
kwargs={'document_root': join(settings.MEDIA_ROOT, settings.AVATAR_PATH)}),
The issue with the Django serve view is that it determines the Content-Type of the response by the file extension in the URL path. Therefore, an attacker can upload an image that contains malicious HTML code and name the file with a .html extension to be rendered as a HTML page. The only file extension validation is performed on the client-side, which can be easily bypassed.
Proof of Concept
Below are the steps to reproduce this issue and execute JavaScript code in the context of the Label Studio website.
- Using any JPEG or PNG image, add in the comment field in the metadata the HTML code
<script>alert(document.domain)</script>. This can be done using theexiftoolcommand as shown below that was used to create the following image.
exiftool -Comment='<script>alert(document.domain)</script>' penguin.jpg

-
On Label Studio, navigate to account & settings page and intercept the upload request of the avatar image using a tool such as Burp Suite. Modify the filename in the request to have a
.htmlextension. -
Right click the image on the avatar profile and copy the URL. Send this to a victim and it will display an alert box with the host name of the Label Studio instance as shown below.

Impact
Executing arbitrary JavaScript could result in an attacker performing malicious actions on Label Studio users if they visit the crafted avatar image. For an example, an attacker can craft a JavaScript payload that adds a new Django Super Administrator user if a Django administrator visits the image.
Remediation Advice
- Validate the file extension on the server side, not in client-side code.
- Remove the use of Django's
serveview and implement a secure controller for viewing uploaded avatar images. - Consider saving file content in the database rather than on the filesystem to mitigate against other file related vulnerabilities.
- Avoid trusting user controlled inputs.
Discovered
- August 2023, Alex Brown, elttam
Affected Packages
| Ecosystem | Package | Vulnerable range | Fix |
|---|---|---|---|
| 🐍PyPI | label-studio | all versions | 1.9.2pip install --upgrade 'label-studio==1.9.2' |
Research use only. For defensive security, authorized penetration testing, and academic research only. Never execute exploit code against systems without explicit written authorization.
Detection & mitigation playbook
Open-source dependencyDetect
Scan your dependency tree (package-lock.json, pnpm-lock.yaml, requirements.txt, go.sum, etc.) for label-studio, including transitive dependencies — a direct dependency you never call can still pull in a vulnerable version.
Fix
Update label-studio to 1.9.2 or later, then make sure no transitive (indirect) dependency still pins the vulnerable range — O3 confirms GHSA-q68h-xwq5-mm7x is resolved across your whole dependency graph.
Workarounds
If you can't upgrade right away: gate or disable the affected feature, validate untrusted input at the boundary, and avoid passing attacker-controlled data into the vulnerable path. O3's runtime protection blocks exploitation in production as an interim safeguard until the upgrade lands.
How O3 protects you
O3 Security's impact-aware SCA analyses which vulnerable code paths your application actually calls, so a match like GHSA-q68h-xwq5-mm7x can be triaged on real exposure rather than presence alone.
Tailored to GHSA-q68h-xwq5-mm7x. Runtime protection reduces exposure until a permanent patch is applied and verified — it complements patching, it doesn't replace it.
How to detect GHSA-q68h-xwq5-mm7x
A community-maintained Nuclei template exists for this CVE. You can scan for it directly:
nuclei -id ghsa-q68h-xwq5-mm7x -u https://target- Template
- Label Studio - Cross-Site Scripting
- Severity
- high
- Impact
- Executing arbitrary JavaScript could result in an attacker performing malicious actions on Label Studio users if they visit the crafted avatar image.
- Remediation
- Update to version 1.9.2.
Template by ProjectDiscovery nuclei-templates (isacaya), MIT licensed. View the full template. Scan only systems you are authorised to test.
Frequently Asked Questions
Is GHSA-q68h-xwq5-mm7x in your dependencies?
O3 Security finds GHSA-q68h-xwq5-mm7x across PyPI dependencies, including transitive ones, and its impact-aware SCA ranks findings by whether your code actually calls the vulnerable path.