Cyber Resilience

CVE-2025-25297

SSRF in Humansignal Label Studio ≤ 1.16.0

Public PoCSSRF
Published
14 February 2025
Modified
25 August 2025
Patch / advisory
CVSS Score v3.1 8.6
Click a component to see what it means
Raw vectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N
EPSS Score 0.0064 48th percentile
Risk Priority 62 floored blend · peak EPSS

Summary

CVE-2025-25297 is a high-severity SSRF (CWE-918) vulnerability in Humansignal Label Studio. Its CVSS base score is 8.6 (High).

Operationally, exploitation aligns with the MITRE ATT&CK technique Exploit Public-Facing Application (T1190); ranked at the 48th percentile by exploit likelihood (below the median); it is not currently listed in the CISA KEV catalog; a public proof-of-concept is referenced.

The strongest mitigations our analysis identified map to AC-4 (Information Flow Enforcement) and SI-10 (Information Input Validation) — see the control section below for these in your framework.

Deeper analysis AI-assisted summary

Synthesised by an AI model from the NVD description and linked references — a reading aid, not an authoritative source.

CVE-2025-25297 is a Server-Side Request Forgery (SSRF) vulnerability, classified under CWE-918, affecting Label Studio, an open-source data labeling tool, in versions prior to 1.16.0. The issue resides in the S3 storage integration feature, specifically the endpoint configuration. When creating an S3 storage connection, users can specify a custom S3 endpoint URL via the s3_endpoint parameter, which is passed directly to the boto3 AWS SDK without validation of the protocol or destination. This allows arbitrary HTTP requests to internal services when the storage sync operation is triggered.

Unauthenticated remote attackers (AV:N/AC:L/PR:N/UI:N) can exploit this vulnerability over the network with low complexity and no user interaction. By setting the s3_endpoint to target internal services, attackers cause the application to issue S3 API calls to those endpoints during sync operations. The responses from these requests appear in error messages, including full response bodies, enabling attackers to bypass network segmentation, access otherwise isolated internal services, and exfiltrate sensitive data. The vulnerability has a CVSS v3.1 base score of 8.6, with high confidentiality impact and changed scope (S:C/C:H/I:N/A:N).

The patch is available in Label Studio version 1.16.0. Official advisories and the fixing commit are documented on GitHub at https://github.com/HumanSignal/label-studio/security/advisories/GHSA-m238-fmcw-wh58 and https://github.com/HumanSignal/label-studio/commit/06a2b29c1208e1878ccae66e6b84c8b24598fa79.

Label Studio's role as a data labeling tool gives this vulnerability relevance to AI/ML workflows, where it may be deployed to annotate datasets for model training. No public information on real-world exploitation is available.

OWASP Top 10 for Web (2025)

EU & UK References

Vulnerability Data

Label Studio is an open source data labeling tool. Prior to version 1.16.0, Label Studio's S3 storage integration feature contains a Server-Side Request Forgery (SSRF) vulnerability in its endpoint configuration. When creating an S3 storage connection, the application allows users…

more

to specify a custom S3 endpoint URL via the s3_endpoint parameter. This endpoint URL is passed directly to the boto3 AWS SDK without proper validation or restrictions on the protocol or destination. The vulnerability allows an attacker to make the application send HTTP requests to arbitrary internal services by specifying them as the S3 endpoint. When the storage sync operation is triggered, the application attempts to make S3 API calls to the specified endpoint, effectively making HTTP requests to the target service and returning the response in error messages. This SSRF vulnerability enables attackers to bypass network segmentation and access internal services that should not be accessible from the external network. The vulnerability is particularly severe because error messages from failed requests contain the full response body, allowing data exfiltration from internal services. Version 1.16.0 contains a patch for the issue.

CWE(s)

Related Threats

MITRE ATT&CK Enterprise Techniques

T1190 Exploit Public-Facing Application Initial Access
Adversaries may attempt to exploit a weakness in an Internet-facing host or system to initially access a network.
Derived from this CVE’s CWE(s) via the direct CWE→ATT&CK cross-walk.

CVEs Like This One

CVE-2023-47116Same product: Humansignal Label Studio
CVE-2024-26152Same product: Humansignal Label Studio
CVE-2025-47783Same product: Humansignal Label Studio
CVE-2025-25296Same product: Humansignal Label Studio
CVE-2026-22033Same product: Humansignal Label Studio
CVE-2023-47117Same product: Humansignal Label Studio
CVE-2023-43791Same product: Humansignal Label Studio
CVE-2023-47115Same product: Humansignal Label Studio
CVE-2024-23633Same product: Humansignal Label Studio
CVE-2025-46568Shared CWE-918

Affected Assets

humansignal
label studio
≤ 1.16.0

Mitigating Controls

Control response

Prevent
Stop it (NIST 800-53)

Detect
Catch it (NIST detect / respond)

Harden
Shrink the surface (DISA STIG)

Validate
Prove the fix (OWASP ASVS)
  • V1.3.6
  • V1.5.3
  • V5.3.2
  • V10.4.7

Mitigating Controls (NIST 800-53 r5) AI

Information flow enforcement can restrict which destinations the server is allowed to contact on behalf of users.

Input validation directly stops untrusted URLs from being accepted and fetched without destination checks.

Boundary protection limits the network reach of server-initiated requests even if SSRF occurs.

Mitigating Controls (NIST CSF 2.0) AI

Derived directly from the weakness types (CWEs) cited in the NVD entry via our AI-authored CWE→CSF cross-walk (authority under review) — links open the control.

PR.PS-06 mostly match
prevents

Secure development practices directly include input validation and destination allow-listing that prevent SSRF.

DE.CM-09 partial match
prevents

Runtime monitoring of web applications and services can detect anomalous outbound requests indicative of SSRF.

ID.RA-01 partial match
prevents

Vulnerability identification processes can discover and record SSRF flaws in web applications.

PR.IR-01 partial match
prevents

Network segmentation and egress controls can limit the damage from successful SSRF requests.

Mitigating Controls (ISO/IEC 27001:2022 Annex A) AI

Derived directly from the weakness types (CWEs) cited in the NVD entry via our AI-authored CWE→ISO cross-walk (authority under review) — links open the control.

prevents

Operational threat data describing SSRF campaigns can be used to tighten outbound-request allow-lists and detection rules before attackers exploit them.

References