CVE-2025-25296 affects Label Studio prior to version 1.16.0. The /projects/upload-example endpoint accepts a label_config query parameter via a GET request and renders attacker-controlled content without proper sanitization. By supplying a specially crafted XML label configuration containing inline task data with malicious HTML or JavaScript, an attacker can trigger cross-site scripting in a victim's browser. Although Label Studio deploys a Content Security Policy, it is configured in report-only mode and therefore does not block script execution. The issue stems from unsafe rendering of user-provided HTML in the upload-example endpoint.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
/projects/upload-example endpoint where feasible, especially from untrusted users. Avoid opening untrusted Label Studio links containing attacker-supplied label_config parameters. Enforce a blocking Content Security Policy rather than report-only mode, recognizing that CSP should be treated as defense in depth rather than a substitute for server-side sanitization.Patch, then assume compromise.
label_config is properly sanitized or encoded before rendering, and unsafe HTML/JavaScript injection paths should be eliminated.2 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos.
This repository is a small standalone proof-of-concept for CVE-2025-25296, a cross-site scripting issue in Label Studio’s /projects/upload-example endpoint. The repo contains 5 files: a README with vulnerability description and usage, a Python exploit script (poc.py), a dependency list, a shell setup script, and a .gitignore. The main exploit logic is entirely in poc.py. It defines a hardcoded target URL of http://localhost:8080/projects/upload-example/ and constructs a malicious label_config value containing Label Studio view markup with embedded HTML and an <img> tag whose onerror handler executes JavaScript via eval(atob(...)). The script URL-encodes this payload, sends it in a GET request, and if the server responds with HTTP 200, prints the resulting URL for the operator to open manually in a browser. This means the exploit does not itself deliver a shell or server-side code execution; it demonstrates client-side arbitrary JavaScript execution in the browser context of whoever opens the crafted URL. setup.sh is not exploit logic but prepares a local vulnerable lab by installing Python requirements, pulling heartexlabs/label-studio:1.15.0, and running it on port 8080 with a mounted data directory. Overall, this is a genuine exploit POC, not a detection script, and its capability is limited to demonstrating reflected or rendered XSS against vulnerable Label Studio instances.
This repository is a Proof of Concept (POC) exploit for CVE-2025-25296, a Cross-Site Scripting (XSS) vulnerability in Label Studio version 1.15.0. The repository contains five files: a Python exploit script (poc.py), a Bash setup script (setup.sh), a requirements file, a README, and a .gitignore. The setup script uses Docker to deploy a vulnerable Label Studio instance on localhost:8080. The main exploit (poc.py) crafts a malicious GET request to the /projects/upload-example endpoint, embedding a JavaScript payload in the label_config parameter. When the generated URL is opened in a browser, the payload triggers a JavaScript alert, demonstrating the XSS vulnerability. The exploit is a POC and does not provide weaponized or post-exploitation capabilities. The repository is well-documented and intended for educational and research purposes only.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.