Impact
A flaw in the Bulk-Delete Endpoint for the LabelList function under /v1/projects/1/category-types permits improper access control. Attackers can manipulate the request to bypass authorization checks, causing the deletion of category types or labels and erasing vital training data. This represents a privilege‑escalation or data‑destruction scenario as described by CWE‑266 and CWE‑284.
Affected Systems
The vulnerability is present in Doccano Open Source Annotation Tools for Machine Learning Practitioners and the Auto Labeling Pipeline Module to Annotate a Document Automatically up to version 1.8.5. Any deployment of these products running the affected codebase is potentially compromised.
Risk and Exploitability
The CVSS score of 5.3 indicates moderate severity. The EPSS score is not available and the vulnerability is not listed in CISA’s KEV catalog. Nevertheless, the exploit has been released publicly and remote exploitation is possible, suggesting that a determined attacker could leverage the API to delete category types without proper authorization. Given the lack of a vendor response and patch, the risk remains present until mitigation is applied.
OpenCVE Enrichment