HIGHCVSS 8.5Vulnerability

CVE-2026-85179

Label Studio through 1.23.0 fails to validate webhook URLs, allowing authenticated users to dispatch requests to internal services including RFC 1918 addresses and cloud metadata endpoints. Attackers can create webhooks targeting private networks and exfiltrate annotation data by enabling payload transmission in outbound requests.

Properties

severity
HIGH
cvss_severity
HIGH
cvss_score
8.5
retrieved_at
2026-09-25T15:10:08+00:00
score
8.5
last_source
NVD
cve_id
CVE-2026-85179
cvss_vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:N
signal_observed_at
2026-09-25T15:10:08+00:00
vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:N
published_at
2026-09-03T15:17:39.097
last_modified
2026-09-24T20:43:32.537

Related Entities (2)

DESCRIBED_BY (1)

→[Source]NVD

HAS_WEAKNESS (1)

→[Weakness]Server-Side Request Forgery (SSRF)

Explore deeper with Ninja Signal's threat intelligence graph

CVE-2026-85179 (CVSS 8.5) — Ninja Signal Threat Intelligence | Ninja Signal