humansignal
Security Risk Profile
Security Risk Score
Comprehensive risk assessment based on 12 vulnerabilities, EPSS scores, exploitation status, and remediation availability.
📅 Data spans from November 9, 2023 to present
Threat Assessment
Severity Distribution
Exploit Likelihood
Age Distribution
Common Weaknesses (CWE)
Most Affected Products
Recent Vulnerabilities
See more →HumanSignal Label Studio - Server-Side Request Forgery
Label Studio vulnerable to full account takeover by chaining Stored XSS + IDOR in User Profile via custom_hotkeys field
HumanSignal label-studio-ml-backend PT File neural_nets.py load deserialization
label-studio vulnerable to Cross-Site Scripting (Reflected) via the label_config parameter.
Label Studio allows Server-Side Request Forgery in the S3 Storage Endpoint
Label Studio allows Cross-Site Scripting (XSS) via GET request to `/projects/upload-example` endpoint
Label Studio vulnerable to Cross-site Scripting if `<Choices>` or `<Labels>` are used in labeling config
Label Studio SSRF on Import Bypassing `SSRF_PROTECTION_ENABLED` Protections
Label Studio XSS Vulnerability on Data Import
Label Studio XSS Vulnerability on Avatar Upload
Monitor humansignal in Real-Time
Get instant alerts when new vulnerabilities are discovered. Stay ahead of security threats with SecAlerts.