Label Studio versions through 1.23.0 contain a vulnerability in proxy_api.py that fails to apply organization filters when resolving storage URIs for tasks and projects. This flaw enables attackers to access other tenants' cloud storage objects in a multi-tenant environment. An attacker can exploit this by creating a separate organization and supplying arbitrary file URIs to presign or stream bucket contents belonging to other organizations. The vulnerability represents a broken access control issue with significant data exposure implications for multi-tenant deployments. It was reported via GitHub issue #9924 and documented by VulnCheck. No patch version has been specified beyond the affected version 1.23.0.