MEDIUM
HumanSignal
CVE published 2026-08-11
CVE-2026-72560
A server-side request forgery vulnerability exists in HumanSignal Label Studio through 1.24.0.dev0. The import-from-URL endpoint can fetch any caller-supplied URL, including internal loopback addresses, on the default installation. This allows an authenticated user to reach internal services, cloud metadata endpoints, and other resources not intended for external access because SSRF_PROTECTION_ENABLED is [truncated]