CVE-2023-47115: Label Studio XSS Vulnerability on Avatar Upload

Published Jan 23, 2024
·
Updated

Introduction

This write-up describes a vulnerability found in Label Studio, a popular open source data labeling tool. The vulnerability affects all versions of Label Studio prior to 1.9.2 and was tested on version 1.8.2.

Overview

Label Studio has a cross-site scripting (XSS) vulnerability that could be exploited when an authenticated user uploads a crafted image file for their avatar that gets rendered as a HTML file on the website.

Description

The following code snippet in Label Studio shows that the only verification check is that the file is an image by extracting the dimensions from the file.

python

def hashupload(instance, filename): filename = str(uuid.uuid4())[0:8] + '-' + filename return settings.AVATARPATH + '/' + filename <3>

def checkavatar(files): images = list(files.items()) if not images: return None

filename, avatar = list(files.items())[0] # get first file w, h = getimagedimensions(avatar) <1> if not w or not h: raise forms.ValidationError("Can't read image, try another one")

# validate dimensions maxwidth = maxheight = 1200 if w > maxwidth or h > maxheight: raise forms.ValidationError('Please use an image that is %s x %s pixels or smaller.' % (maxwidth, maxheight))

# validate content type main, sub = avatar.contenttype.split('/') <2> if not (main == 'image' and sub.lower() in ['jpeg', 'jpg', 'gif', 'png']): raise forms.ValidationError(u'Please use a JPEG, GIF or PNG image.')

# validate file size maxsize = 1024 1024 if len(avatar) > maxsize: raise forms.ValidationError('Avatar file size may not exceed ' + str(maxsize/1024) + ' kb')

return avatar 1. Attempts to get image dimensions to validate the uploaded avatar file is an image. 2. Extracts the Content-Type from the upload POST request. A user can easily bypass this verification by changing the mimetype of the uploaded file to an allowed type (eg. image/jpeg). 3. The file extension of the uploaded file is never validated and is saved to the filesystem.

Label Studio serves avatar images using Django's built-in serve view, which is not secure for production use according to Django's documentation.

python repath(r'^data/' + settings.AVATARPATH + '/(?P<path>.)$', serve, kwargs={'documentroot': join(settings.MEDIAROOT, settings.AVATARPATH)}),

The issue with the Django serve view is that it determines the Content-Type of the response by the file extension in the URL path. Therefore, an attacker can upload an image that contains malicious HTML code and name the file with a .html extension to be rendered as a HTML page. The only file extension validation is performed on the client-side, which can be easily bypassed.

Proof of Concept

Below are the steps to reproduce this issue and execute JavaScript code in the context of the Label Studio website.

1. Using any JPEG or PNG image, add in the comment field in the metadata the HTML code <script>alert(document.domain)</script>. This can be done using the exiftool command as shown below that was used to create the following image.

bash exiftool -Comment='<script>alert(document.domain)</script>' penguin.jpg

!xss-penguin

2. On Label Studio, navigate to account & settings page and intercept the upload request of the avatar image using a tool such as Burp Suite. Modify the filename in the request to have a .html extension.

3. Right click the image on the avatar profile and copy the URL. Send this to a victim and it will display an alert box with the host name of the Label Studio instance as shown below.

!xss-alert

Impact

Executing arbitrary JavaScript could result in an attacker performing malicious actions on Label Studio users if they visit the crafted avatar image. For an example, an attacker can craft a JavaScript payload that adds a new Django Super Administrator user if a Django administrator visits the image.

Remediation Advice

Validate the file extension on the server side, not in client-side code. Remove the use of Django's serve view and implement a secure controller for viewing uploaded avatar images. Consider saving file content in the database rather than on the filesystem to mitigate against other file related vulnerabilities. Avoid trusting user controlled inputs.

Discovered - August 2023, Alex Brown, elttam

Other sources

Label Studio is an a popular open source data labeling tool. Versions prior to 1.9.2 have a cross-site scripting (XSS) vulnerability that could be exploited when an authenticated user uploads a crafted image file for their avatar that gets rendered as a HTML file on the website. Executing arbitrary JavaScript could result in an attacker performing malicious actions on Label Studio users if they visit the crafted avatar image. For an example, an attacker can craft a JavaScript payload that adds a new Django Super Administrator user if a Django administrator visits the image.

The file users/functions.py lines 18-49 show that the only verification check is that the file is an image by extracting the dimensions from the file. Label Studio serves avatar images using Django's built-in serve view, which is not secure for production use according to Django's documentation. The issue with the Django serve view is that it determines the Content-Type of the response by the file extension in the URL path. Therefore, an attacker can upload an image that contains malicious HTML code and name the file with a .html extension to be rendered as a HTML page. The only file extension validation is performed on the client-side, which can be easily bypassed.

Version 1.9.2 fixes this issue. Other remediation strategies include validating the file extension on the server side, not in client-side code; removing the use of Django's serve view and implement a secure controller for viewing uploaded avatar images; saving file content in the database rather than on the filesystem to mitigate against other file related vulnerabilities; and avoiding trusting user controlled inputs.

MITRE

Affected Software

2 affected componentsFixes available
pip/label-studio<1.9.2
1.9.2
HumanSignal Label Studio<1.9.2

Event History

Jan 23, 2024
CVE Published
via MITRE·10:49 PM
Data Sourced
via MITRE·10:49 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·11:15 PM
DescriptionSeverityWeakness
Jan 24, 2024
Advisory Published
via GitHub·02:21 PM

Frequently Asked Questions

1

What is the severity of CVE-2023-47115?

CVE-2023-47115 has a severity rating as defined by the Common Vulnerability Scoring System, highlighting its potential risk.

2

How do I fix CVE-2023-47115?

To fix CVE-2023-47115, update Label Studio to version 1.9.2 or later.

3

Which versions of Label Studio are affected by CVE-2023-47115?

CVE-2023-47115 affects all versions of Label Studio prior to 1.9.2.

4

What is the nature of the vulnerability in CVE-2023-47115?

CVE-2023-47115 is a security vulnerability affecting the Label Studio application related to user management.

5

Is there a workaround for CVE-2023-47115?

No official workaround is available for CVE-2023-47115 other than upgrading to a patched version.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203