CVE-2026-85211

Label Studio fails to apply organization filters when resolving storage URIs for tasks and projects in proxy_api.py endpoints. Attackers can access other tenants' cloud storage objects by creating a separate organization and supplying arbitrary file URIs to presign or stream bucket contents.

  • Published Sep 3, 2026
  • CVSS 8.3 high
  • 0.4% chance of exploitation in the next 30 days (EPSS)

Affected software

CVE-2026-85211 at the National Vulnerability Database