Skip to content

1.23.2

Latest

Choose a tag to compare

@robot-ci-heartex robot-ci-heartex released this 29 Sep 14:47

⚠️ Upgrade notes

  • pip installs: rotate your SECRET_KEY if other users on the machine can read your data directory. Older versions saved the generated SECRET_KEY in <data_dir>/.env (~/.local/share/label-studio/.env on Linux) with permissions that let any local user read it. This release makes the file readable only by its owner, but a key that may already have been read stays valid until you change it. To rotate it, delete the SECRET_KEY line from .env (or set a new SECRET_KEY environment variable) and restart. Everyone will need to log in again, and existing access tokens stop working.
  • Image exports skip media on private networks. When SSRF_PROTECTION_ENABLED=true (the default), COCO_WITH_IMAGES, YOLO_WITH_IMAGES and YOLO_OBB_WITH_IMAGES exports no longer download media from private or local network addresses. The export still completes, but those images are left out of the archive. If your task media is hosted on an internal server, set USE_DEFAULT_BANNED_SUBNETS=false and list only the ranges you want blocked in USER_ADDITIONAL_BANNED_SUBNETS, or set SSRF_PROTECTION_ENABLED=false.
  • Set LABEL_STUDIO_HOST so image exports can include uploaded files. Exports now download files from Label Studio itself only when its address can be trusted: when LABEL_STUDIO_HOST is set, or when ALLOWED_HOSTS is restricted. On a default install with neither, uploaded files that aren't on the local disk (for example, when the default storage is S3, GCS or Azure) are left out of image exports.
  • Uploaded HTML, SVG and XML files open in a sandbox. When these files are opened from /storage-data/uploaded/, they are served with Content-Security-Policy: sandbox, so scripts inside them don't run. Images, PDFs, audio and video aren't affected. If you run your own reverse proxy instead of the bundled nginx config, add the same header for these content types. See the $uploaded_file_csp map in deploy/default.conf.

Security

  • The generated SECRET_KEY file (<data_dir>/.env) is now created readable only by its owner, and an existing file is restricted on startup. The data directory is also created readable only by its owner.
  • S3-compatible storage endpoints are now checked for private or local addresses every time a connection is opened, not only when the storage is saved. This blocks DNS rebinding. Storages saved before this check existed are also re-checked.
  • Image exports now block media URLs that point at private or local network addresses.
  • Image exports no longer send the organization owner's API token to a host taken from the request's Host header.
  • Uploaded HTML, SVG and XML files served from /storage-data/uploaded/ are sandboxed, both when Django serves them directly and when they are served through the bundled nginx.