PatchSiren

HumanSignal CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM HumanSignal CVE published 2026-08-11

CVE-2026-72560

A server-side request forgery vulnerability exists in HumanSignal Label Studio through 1.24.0.dev0. The import-from-URL endpoint can fetch any caller-supplied URL, including internal loopback addresses, on the default installation. This allows an authenticated user to reach internal services, cloud metadata endpoints, and other resources not intended for external access because SSRF_PROTECTION_ENABLED is [truncated]