Raw vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:NSummary
CVE-2025-25297 is a high-severity SSRF (CWE-918) vulnerability in Humansignal Label Studio. Its CVSS base score is 8.6 (High).
Operationally, exploitation aligns with the MITRE ATT&CK technique Exploit Public-Facing Application (T1190); ranked at the 48th percentile by exploit likelihood (below the median); it is not currently listed in the CISA KEV catalog; a public proof-of-concept is referenced.
The strongest mitigations our analysis identified map to AC-4 (Information Flow Enforcement) and SI-10 (Information Input Validation) — see the control section below for these in your framework.
Deeper analysis AI-assisted summary
Synthesised by an AI model from the NVD description and linked references — a reading aid, not an authoritative source.
CVE-2025-25297 is a Server-Side Request Forgery (SSRF) vulnerability, classified under CWE-918, affecting Label Studio, an open-source data labeling tool, in versions prior to 1.16.0. The issue resides in the S3 storage integration feature, specifically the endpoint configuration. When creating an S3 storage connection, users can specify a custom S3 endpoint URL via the s3_endpoint parameter, which is passed directly to the boto3 AWS SDK without validation of the protocol or destination. This allows arbitrary HTTP requests to internal services when the storage sync operation is triggered.
Unauthenticated remote attackers (AV:N/AC:L/PR:N/UI:N) can exploit this vulnerability over the network with low complexity and no user interaction. By setting the s3_endpoint to target internal services, attackers cause the application to issue S3 API calls to those endpoints during sync operations. The responses from these requests appear in error messages, including full response bodies, enabling attackers to bypass network segmentation, access otherwise isolated internal services, and exfiltrate sensitive data. The vulnerability has a CVSS v3.1 base score of 8.6, with high confidentiality impact and changed scope (S:C/C:H/I:N/A:N).
The patch is available in Label Studio version 1.16.0. Official advisories and the fixing commit are documented on GitHub at https://github.com/HumanSignal/label-studio/security/advisories/GHSA-m238-fmcw-wh58 and https://github.com/HumanSignal/label-studio/commit/06a2b29c1208e1878ccae66e6b84c8b24598fa79.
Label Studio's role as a data labeling tool gives this vulnerability relevance to AI/ML workflows, where it may be deployed to annotate datasets for model training. No public information on real-world exploitation is available.
OWASP Top 10 for Web (2025)
EU & UK References
- 🇪🇺 ENISA EUVD: EUVD-2025-4107
Vulnerability Data
Label Studio is an open source data labeling tool. Prior to version 1.16.0, Label Studio's S3 storage integration feature contains a Server-Side Request Forgery (SSRF) vulnerability in its endpoint configuration. When creating an S3 storage connection, the application allows users…
more
to specify a custom S3 endpoint URL via the s3_endpoint parameter. This endpoint URL is passed directly to the boto3 AWS SDK without proper validation or restrictions on the protocol or destination. The vulnerability allows an attacker to make the application send HTTP requests to arbitrary internal services by specifying them as the S3 endpoint. When the storage sync operation is triggered, the application attempts to make S3 API calls to the specified endpoint, effectively making HTTP requests to the target service and returning the response in error messages. This SSRF vulnerability enables attackers to bypass network segmentation and access internal services that should not be accessible from the external network. The vulnerability is particularly severe because error messages from failed requests contain the full response body, allowing data exfiltration from internal services. Version 1.16.0 contains a patch for the issue.
- CWE(s)
Related Threats
MITRE ATT&CK Enterprise Techniques
CVEs Like This One
Affected Assets
Mitigating Controls
Control response
—
—
—
V1.3.6V1.5.3V5.3.2V10.4.7
Mitigating Controls (NIST 800-53 r5) AI
Information flow enforcement can restrict which destinations the server is allowed to contact on behalf of users.
Input validation directly stops untrusted URLs from being accepted and fetched without destination checks.
Boundary protection limits the network reach of server-initiated requests even if SSRF occurs.
Mitigating Controls (NIST CSF 2.0) AI
Derived directly from the weakness types (CWEs) cited in the NVD entry via our AI-authored CWE→CSF cross-walk (authority under review) — links open the control.
Secure development practices directly include input validation and destination allow-listing that prevent SSRF.
Runtime monitoring of web applications and services can detect anomalous outbound requests indicative of SSRF.
Vulnerability identification processes can discover and record SSRF flaws in web applications.
Network segmentation and egress controls can limit the damage from successful SSRF requests.
Mitigating Controls (ISO/IEC 27001:2022 Annex A) AI
Derived directly from the weakness types (CWEs) cited in the NVD entry via our AI-authored CWE→ISO cross-walk (authority under review) — links open the control.
Operational threat data describing SSRF campaigns can be used to tighten outbound-request allow-lists and detection rules before attackers exploit them.