CVE-2024-23633
Python vulnerability analysis and mitigation

Overview

A Cross-Site Scripting (XSS) vulnerability was discovered in Label Studio's data import feature affecting all versions prior to 1.10.1. The vulnerability (CVE-2024-23633) was identified in January 2024 and allowed attackers to execute malicious JavaScript code in the context of the Label Studio website through the remote import feature (Label Studio Advisory).

Technical details

The vulnerability existed in Label Studio's remote import functionality where files downloaded from external URLs were not properly sanitized. The issue stemmed from the Content-Type being determined by the file extension using mimetypes.guess_type, allowing attackers to upload HTML files containing malicious JavaScript that would execute when viewed. The vulnerability has a CVSS v3.1 score of 4.7 (Moderate) with vector string CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:N/A:N (Label Studio Advisory).

Impact

When exploited, this vulnerability could allow attackers to execute arbitrary JavaScript code in the context of the Label Studio website. This could potentially lead to malicious actions being performed on behalf of Label Studio users who visit crafted content, including the possibility of adding unauthorized administrator accounts if accessed by a Django administrator (Label Studio Advisory).

Exploitability

The vulnerability requires an attacker to host a malicious HTML file on an external website and trick a user into importing and viewing that file through Label Studio's interface. The attack involves multiple steps including downloading the malicious file via the import API and retrieving the file path through specific API endpoints (Label Studio Advisory).

Mitigation and workarounds

The vulnerability has been patched in Label Studio version 1.10.1. The recommended mitigation includes setting the Content-Security-Policy: sandbox; response header for all user-provided files downloaded by Label Studio, and restricting the allowed file extensions that can be downloaded (Label Studio Advisory).

Additional resources


SourceThis report was generated using AI

Related Python vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-61539CRITICAL10
  • Python logoPython
  • xinference
NoYesAug 21, 2026
CVE-2026-49360HIGH7.8
  • Python logoPython
  • recce
NoYesAug 21, 2026
CVE-2026-68508HIGH7.8
  • Python logoPython
  • hydra-core
NoYesAug 21, 2026
CVE-2026-43980MEDIUM6.3
  • Python logoPython
  • malla
NoNoAug 21, 2026
CVE-2026-55468MEDIUM4.3
  • Python logoPython
  • wagtail
NoYesAug 24, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management