⚠️ Upgrade notes
- pip installs: rotate your
SECRET_KEYif other users on the machine can read your data directory. Older versions saved the generatedSECRET_KEYin<data_dir>/.env(~/.local/share/label-studio/.envon Linux) with permissions that let any local user read it. This release makes the file readable only by its owner, but a key that may already have been read stays valid until you change it. To rotate it, delete theSECRET_KEYline from.env(or set a newSECRET_KEYenvironment variable) and restart. Everyone will need to log in again, and existing access tokens stop working. - Image exports skip media on private networks. When
SSRF_PROTECTION_ENABLED=true(the default),COCO_WITH_IMAGES,YOLO_WITH_IMAGESandYOLO_OBB_WITH_IMAGESexports no longer download media from private or local network addresses. The export still completes, but those images are left out of the archive. If your task media is hosted on an internal server, setUSE_DEFAULT_BANNED_SUBNETS=falseand list only the ranges you want blocked inUSER_ADDITIONAL_BANNED_SUBNETS, or setSSRF_PROTECTION_ENABLED=false. - Set
LABEL_STUDIO_HOSTso image exports can include uploaded files. Exports now download files from Label Studio itself only when its address can be trusted: whenLABEL_STUDIO_HOSTis set, or whenALLOWED_HOSTSis restricted. On a default install with neither, uploaded files that aren't on the local disk (for example, when the default storage is S3, GCS or Azure) are left out of image exports. - Uploaded HTML, SVG and XML files open in a sandbox. When these files are opened from
/storage-data/uploaded/, they are served withContent-Security-Policy: sandbox, so scripts inside them don't run. Images, PDFs, audio and video aren't affected. If you run your own reverse proxy instead of the bundled nginx config, add the same header for these content types. See the$uploaded_file_cspmap indeploy/default.conf.
Security
- The generated
SECRET_KEYfile (<data_dir>/.env) is now created readable only by its owner, and an existing file is restricted on startup. The data directory is also created readable only by its owner. - S3-compatible storage endpoints are now checked for private or local addresses every time a connection is opened, not only when the storage is saved. This blocks DNS rebinding. Storages saved before this check existed are also re-checked.
- Image exports now block media URLs that point at private or local network addresses.
- Image exports no longer send the organization owner's API token to a host taken from the request's
Hostheader. - Uploaded HTML, SVG and XML files served from
/storage-data/uploaded/are sandboxed, both when Django serves them directly and when they are served through the bundled nginx.