{"data":{"ecosystem":"pypi","name":"gradio","url":"https://aisecwatch.com/packages/pypi/gradio","latestVersion":"6.30.0","firstReleaseAt":"2019-02-19T08:25:48.237Z","repository":"https://github.com/gradio-app/gradio","llm":{"exposure":"direct","depth":0,"integratedAt":"2023-03-14T01:12:17.694Z","integratedVersion":"3.21.0","sdks":["huggingface","mcp"],"path":[]},"authority":{"profile":["http","mcp_tools"],"fromDependencies":["pypi:httpx","pypi:mcp"]},"dependencies":[{"ecosystem":"pypi","name":"gradio-client","versionSpec":"==2.7.2","scope":"runtime"},{"ecosystem":"pypi","name":"huggingface-hub","versionSpec":"<3.0,>=1.16.0","scope":"runtime"},{"ecosystem":"pypi","name":"mcp","versionSpec":"<2.0.0,>=1.21.0","scope":"extra:mcp"},{"ecosystem":"pypi","name":"hf-gradio","versionSpec":"<1.0,>=0.4.1","scope":"runtime"},{"ecosystem":"pypi","name":"anyio","versionSpec":"<5.0,>=3.0","scope":"runtime"},{"ecosystem":"pypi","name":"audioop-lts","versionSpec":"<=0.2.2","scope":"runtime"},{"ecosystem":"pypi","name":"authlib","versionSpec":null,"scope":"extra:oauth"},{"ecosystem":"pypi","name":"brotli","versionSpec":">=1.1.0","scope":"runtime"},{"ecosystem":"pypi","name":"fastapi","versionSpec":"<1.0,>=0.115.2","scope":"runtime"},{"ecosystem":"pypi","name":"groovy","versionSpec":"~=0.1","scope":"runtime"},{"ecosystem":"pypi","name":"httpx","versionSpec":"<1.0,>=0.24.1","scope":"runtime"},{"ecosystem":"pypi","name":"itsdangerous","versionSpec":null,"scope":"extra:oauth"},{"ecosystem":"pypi","name":"jinja2","versionSpec":"<4.0","scope":"runtime"},{"ecosystem":"pypi","name":"markupsafe","versionSpec":"<4.0,>=2.0","scope":"runtime"},{"ecosystem":"pypi","name":"numpy","versionSpec":"<3.0,>=1.0","scope":"runtime"},{"ecosystem":"pypi","name":"orjson","versionSpec":"~=3.0","scope":"runtime"},{"ecosystem":"pypi","name":"packaging","versionSpec":null,"scope":"runtime"},{"ecosystem":"pypi","name":"pandas","versionSpec":"<4.0,>=1.0","scope":"runtime"},{"ecosystem":"pypi","name":"pillow","versionSpec":"<13.0,>=8.0","scope":"runtime"},{"ecosystem":"pypi","name":"pydantic","versionSpec":"<=3.0,>=2.0","scope":"runtime"},{"ecosystem":"pypi","name":"pydub","versionSpec":"<1.0","scope":"runtime"},{"ecosystem":"pypi","name":"python-multipart","versionSpec":"<1.0,>=0.0.18","scope":"runtime"},{"ecosystem":"pypi","name":"pytz","versionSpec":">=2017.2","scope":"runtime"},{"ecosystem":"pypi","name":"pyyaml","versionSpec":"<7.0,>=5.0","scope":"runtime"},{"ecosystem":"pypi","name":"safehttpx","versionSpec":"<0.2.0,>=0.1.7","scope":"runtime"},{"ecosystem":"pypi","name":"semantic-version","versionSpec":"~=2.0","scope":"runtime"},{"ecosystem":"pypi","name":"starlette","versionSpec":"<2.0,>=1.0.1","scope":"runtime"},{"ecosystem":"pypi","name":"tomlkit","versionSpec":"<0.15.0,>=0.12.0","scope":"runtime"},{"ecosystem":"pypi","name":"typer","versionSpec":"<1.0,>=0.12","scope":"runtime"},{"ecosystem":"pypi","name":"typing-extensions","versionSpec":"~=4.0","scope":"runtime"},{"ecosystem":"pypi","name":"uvicorn","versionSpec":">=0.14.0","scope":"runtime"}],"advisories":[{"id":"7d61bcc0-9e0a-4c3e-96e9-e79ddfb5fe22","url":"https://aisecwatch.com/issues/7d61bcc0-9e0a-4c3e-96e9-e79ddfb5fe22","cveId":"CVE-2026-49119","title":"CVE-2026-49119: Gradio before 6.16.0 contain a path traversal vulnerability in the FileExplorer component's preprocess() method that…","headline":"Gradio FileExplorer path traversal in preprocess() method","severity":"high","publishedAt":"2026-07-01T19:16:52.463Z","affected":["gradio@< 6.16.0 (fixed: 6.16.0)"],"epssScore":0.0069,"matchedBy":"ecosystem"},{"id":"7703b21f-1c0d-4ed4-89dc-de0eef924195","url":"https://aisecwatch.com/issues/7703b21f-1c0d-4ed4-89dc-de0eef924195","cveId":"CVE-2026-48545","title":"CVE-2026-48545: Gradio before version 6.15.0 contains a cookie injection vulnerability that allows remote attackers to perform…","headline":"Gradio cookie injection through shared proxy HTTP client","severity":"medium","publishedAt":"2026-05-27T15:16:31.020Z","affected":["gradio@< 6.15.0 (fixed: 6.15.0)"],"epssScore":0.0047,"matchedBy":"ecosystem"},{"id":"50e12e7f-0738-4818-a24b-c3d40e33a1b3","url":"https://aisecwatch.com/issues/50e12e7f-0738-4818-a24b-c3d40e33a1b3","cveId":"CVE-2026-28416","title":"CVE-2026-28416: Gradio is an open-source Python package designed for quick prototyping. Prior to version 6.6.0, a Server-Side Request…","headline":"Gradio server-side request forgery when loading a Space with gr.load()","severity":"high","publishedAt":"2026-02-27T22:16:24.667Z","affected":["gradio@< 6.6.0 (fixed: 6.6.0)"],"epssScore":0.00348,"matchedBy":"ecosystem"},{"id":"531fdfda-d087-4a3a-ba97-71bf904e32a4","url":"https://aisecwatch.com/issues/531fdfda-d087-4a3a-ba97-71bf904e32a4","cveId":"CVE-2026-28415","title":"CVE-2026-28415: Gradio is an open-source Python package designed for quick prototyping. Prior to version 6.6.0, the…","headline":"Gradio OAuth open redirect via _target_url on /logout and /login/callback","severity":"medium","publishedAt":"2026-02-27T22:16:24.497Z","affected":["gradio@< 6.6.0 (fixed: 6.6.0)"],"epssScore":0.00294,"matchedBy":"ecosystem"},{"id":"f67c65fb-7524-4bea-83a3-4833eb3ef961","url":"https://aisecwatch.com/issues/f67c65fb-7524-4bea-83a3-4833eb3ef961","cveId":"CVE-2026-28414","title":"CVE-2026-28414: Gradio is an open-source Python package designed for quick prototyping. Prior to version 6.7, Gradio apps running on…","headline":"Gradio absolute path traversal on Windows with Python 3.13+ file read","severity":"high","publishedAt":"2026-02-27T22:16:24.330Z","affected":["gradio@< 6.7.0 (fixed: 6.7.0)"],"epssScore":0.02485,"matchedBy":"ecosystem"},{"id":"39405a90-69b9-49c9-9a94-41abf4bc0f08","url":"https://aisecwatch.com/issues/39405a90-69b9-49c9-9a94-41abf4bc0f08","cveId":"CVE-2026-27167","title":"CVE-2026-27167: Gradio is an open-source Python package designed for quick prototyping. Starting in version 4.16.0 and prior to version…","headline":"Gradio token leak through mocked OAuth login route","severity":"info","publishedAt":"2026-02-27T22:16:22.820Z","affected":["gradio@>= 4.16.0, < 6.6.0 (fixed: 6.6.0)"],"epssScore":0.00393,"matchedBy":"ecosystem"},{"id":"644abab2-d6f7-49a4-9d7d-169eac06a049","url":"https://aisecwatch.com/issues/644abab2-d6f7-49a4-9d7d-169eac06a049","cveId":"CVE-2025-48889","title":"CVE-2025-48889: Gradio is an open-source Python package that allows quick building of demos and web application for machine learning…","headline":"Gradio arbitrary file copy in flagging feature allows unauthenticated attackers","severity":"medium","publishedAt":"2025-05-30T10:15:28.500Z","affected":["gradio@< 5.31.0 (fixed: 5.31.0)"],"epssScore":0.0066,"matchedBy":"ecosystem"},{"id":"65ee0472-fd34-4110-aa97-c3fd325b64c4","url":"https://aisecwatch.com/issues/65ee0472-fd34-4110-aa97-c3fd325b64c4","cveId":"CVE-2025-5320","title":"CVE-2025-5320: A vulnerability classified as problematic has been found in gradio-app gradio up to 5.29.1. This affects the function…","headline":"gradio-app gradio CORS origin validation flaw allows privilege escalation","severity":"low","publishedAt":"2025-05-29T18:15:38.377Z","affected":["gradio@>= 5.0.0, <= 5.29.1"],"epssScore":0.00256,"matchedBy":"ecosystem"},{"id":"063ca5d4-7df7-4e32-8648-8ac723aecdac","url":"https://aisecwatch.com/issues/063ca5d4-7df7-4e32-8648-8ac723aecdac","cveId":"CVE-2024-8966","title":"CVE-2024-8966: A vulnerability in the file upload process of gradio-app/gradio version @gradio/video@0.10.2 allows for a Denial of…","headline":"Gradio denial of service through multipart boundary processing in file upload","severity":"high","publishedAt":"2025-03-20T14:15:45.340Z","affected":["gradio@<= 5.22.0"],"epssScore":0.0079,"matchedBy":"ecosystem"},{"id":"6219203b-9408-4a9b-98ae-0a7839d3785f","url":"https://aisecwatch.com/issues/6219203b-9408-4a9b-98ae-0a7839d3785f","cveId":"CVE-2024-8021","title":"CVE-2024-8021: An open redirect vulnerability exists in the latest version of gradio-app/gradio. The vulnerability allows an attacker…","headline":"gradio-app/gradio open redirect via URL encoding","severity":"medium","publishedAt":"2025-03-20T14:15:39.260Z","affected":["gradio@<= 4.37.2"],"epssScore":0.00744,"matchedBy":"ecosystem"},{"id":"7676008c-dd75-4bdd-8740-370631503850","url":"https://aisecwatch.com/issues/7676008c-dd75-4bdd-8740-370631503850","cveId":"CVE-2024-12217","title":"CVE-2024-12217: A vulnerability in the gradio-app/gradio repository, version git 67e4044, allows for path traversal on Windows OS. The…","headline":"gradio-app/gradio path traversal on Windows via NTFS alternate data streams","severity":"high","publishedAt":"2025-03-20T14:15:27.560Z","affected":["gradio@<= 5.0.1"],"epssScore":0.00685,"matchedBy":"ecosystem"},{"id":"47035e6c-75df-4a9b-97d5-d029e83342b0","url":"https://aisecwatch.com/issues/47035e6c-75df-4a9b-97d5-d029e83342b0","cveId":"CVE-2024-10648","title":"CVE-2024-10648: A path traversal vulnerability exists in the Gradio Audio component of gradio-app/gradio, as of version git 98cbcae…","headline":"Gradio Audio component path traversal allowing arbitrary file deletion","severity":"medium","publishedAt":"2025-03-20T14:15:18.010Z","affected":["gradio@>= 4.0.0, <= 5.0.0b2"],"epssScore":0.00717,"matchedBy":"ecosystem"},{"id":"bc48a43d-e81b-4505-8eff-33d89efae789","url":"https://aisecwatch.com/issues/bc48a43d-e81b-4505-8eff-33d89efae789","cveId":"CVE-2024-10624","title":"CVE-2024-10624: A Regular Expression Denial of Service (ReDoS) vulnerability exists in the gradio-app/gradio repository, affecting the…","headline":"gradio Datetime component ReDoS via crafted HTTP request","severity":"medium","publishedAt":"2025-03-20T14:15:17.880Z","affected":["gradio@>= 4.38.0, <= 5.0.0-beta.2"],"epssScore":0.01077,"matchedBy":"ecosystem"},{"id":"9a26fbe3-1e75-4068-8509-cb05fdfdf371","url":"https://aisecwatch.com/issues/9a26fbe3-1e75-4068-8509-cb05fdfdf371","cveId":"CVE-2024-10569","title":"CVE-2024-10569: A vulnerability in the dataframe component of gradio-app/gradio (version git 98cbcae) allows for a zip bomb attack. The…","headline":"gradio dataframe component zip bomb denial of service via upload","severity":"medium","publishedAt":"2025-03-20T14:15:17.640Z","affected":["gradio@>= 4.0.0, <= 5.0.0b2"],"epssScore":0.00648,"matchedBy":"ecosystem"},{"id":"cb6e9595-1787-4094-94be-06968dcd14a7","url":"https://aisecwatch.com/issues/cb6e9595-1787-4094-94be-06968dcd14a7","cveId":"CVE-2025-23042","title":"CVE-2025-23042: Gradio is an open-source Python package that allows quick building of demos and web application for machine learning…","headline":"Gradio access control bypass via case-altered file paths","severity":"high","publishedAt":"2025-01-15T00:15:44.863Z","affected":["gradio@< 5.11.0 (fixed: 5.11.0)"],"epssScore":0.00983,"matchedBy":"ecosystem"},{"id":"439c9471-70ff-495b-8b42-0d9ce4727023","url":"https://aisecwatch.com/issues/439c9471-70ff-495b-8b42-0d9ce4727023","cveId":"CVE-2024-51751","title":"CVE-2024-51751: Gradio is an open-source Python package designed to enable quick builds of a demo or web application. If File or…","headline":"Gradio file preview components allow reading arbitrary files on the server","severity":"medium","publishedAt":"2024-11-07T01:15:05.557Z","affected":["gradio@>= 5.0.0, < 5.5.0 (fixed: 5.5.0)"],"epssScore":0.00687,"matchedBy":"ecosystem"},{"id":"1a6fa642-16a0-4eac-976d-ccd02071c217","url":"https://aisecwatch.com/issues/1a6fa642-16a0-4eac-976d-ccd02071c217","cveId":"CVE-2024-48052","title":"CVE-2024-48052: In gradio <=4.42.0, the gr.DownloadButton function has a hidden server-side request forgery (SSRF) vulnerability. The…","headline":"gradio gr.DownloadButton server-side request forgery in save_url_to_cache","severity":"medium","publishedAt":"2024-11-05T04:15:04.337Z","affected":["gradio@<= 4.42.0"],"epssScore":0.0047,"matchedBy":"ecosystem"},{"id":"1bc2d485-546d-4016-bfe8-45c4b3fff0e0","url":"https://aisecwatch.com/issues/1bc2d485-546d-4016-bfe8-45c4b3fff0e0","cveId":"CVE-2024-47872","title":"CVE-2024-47872: Gradio is an open-source Python package designed for quick prototyping. This vulnerability involves **Cross-Site…","headline":"Gradio cross-site scripting through uploaded HTML, JavaScript, or SVG files","severity":"medium","publishedAt":"2024-10-11T03:15:03.303Z","affected":["gradio@< 5.0.0 (fixed: 5.0.0)"],"epssScore":0.00275,"matchedBy":"ecosystem"},{"id":"38a6b11a-eb38-450b-9a71-6200c64cfab4","url":"https://aisecwatch.com/issues/38a6b11a-eb38-450b-9a71-6200c64cfab4","cveId":"CVE-2024-47871","title":"CVE-2024-47871: Gradio is an open-source Python package designed for quick prototyping. This vulnerability involves **insecure…","headline":"Gradio insecure communication between FRP client and server when share=True","severity":"critical","publishedAt":"2024-10-11T03:15:03.187Z","affected":["gradio@< 5.0.0 (fixed: 5.0.0)"],"epssScore":0.00176,"matchedBy":"ecosystem"},{"id":"ba70003b-0f49-4132-bba4-7ddbf1a4740d","url":"https://aisecwatch.com/issues/ba70003b-0f49-4132-bba4-7ddbf1a4740d","cveId":"CVE-2024-47870","title":"CVE-2024-47870: Gradio is an open-source Python package designed for quick prototyping. This vulnerability involves a **race…","headline":"Gradio race condition in update_root_in_config allows backend URL redirection","severity":"high","publishedAt":"2024-10-11T03:15:03.070Z","affected":["gradio@< 5.0.0 (fixed: 5.0.0)"],"epssScore":0.00369,"matchedBy":"ecosystem"},{"id":"a0354f9f-cced-43ca-b0b2-27516f6cedb8","url":"https://aisecwatch.com/issues/a0354f9f-cced-43ca-b0b2-27516f6cedb8","cveId":"CVE-2024-47869","title":"CVE-2024-47869: Gradio is an open-source Python package designed for quick prototyping. This vulnerability involves a **timing attack**…","headline":"Gradio timing attack in hash comparison for analytics_dashboard","severity":"low","publishedAt":"2024-10-11T03:15:02.930Z","affected":["gradio@< 4.44.0 (fixed: 4.44.0)"],"epssScore":0.00292,"matchedBy":"ecosystem"},{"id":"c20ae32a-8443-45dd-adc2-ddf014c3ee71","url":"https://aisecwatch.com/issues/c20ae32a-8443-45dd-adc2-ddf014c3ee71","cveId":"CVE-2024-47868","title":"CVE-2024-47868: Gradio is an open-source Python package designed for quick prototyping. This is a **data validation vulnerability**…","headline":"Gradio arbitrary file leak through post-processing of file data components","severity":"high","publishedAt":"2024-10-11T03:15:02.797Z","affected":["gradio@< 5.0.0 (fixed: 5.0.0)"],"epssScore":0.00815,"matchedBy":"ecosystem"},{"id":"f353b05c-13f0-4aa9-ac32-7efce6a698bf","url":"https://aisecwatch.com/issues/f353b05c-13f0-4aa9-ac32-7efce6a698bf","cveId":"CVE-2024-47867","title":"CVE-2024-47867: Gradio is an open-source Python package designed for quick prototyping. This vulnerability is a **lack of integrity…","headline":"Gradio lack of integrity check on downloaded FRP client","severity":"high","publishedAt":"2024-10-11T03:15:02.640Z","affected":["gradio@< 5.0.0 (fixed: 5.0.0)"],"epssScore":0.00213,"matchedBy":"ecosystem"},{"id":"4dff6515-23ff-4f08-9797-6f844cb79cbc","url":"https://aisecwatch.com/issues/4dff6515-23ff-4f08-9797-6f844cb79cbc","cveId":"CVE-2024-47168","title":"CVE-2024-47168: Gradio is an open-source Python package designed for quick prototyping. This vulnerability involves data exposure due…","headline":"Gradio data exposure through /monitoring endpoint when monitoring is disabled","severity":"medium","publishedAt":"2024-10-11T02:15:11.173Z","affected":["gradio@< 4.44.0 (fixed: 4.44.0)"],"epssScore":0.00332,"matchedBy":"ecosystem"},{"id":"60ea1a9f-4810-4761-a4bd-c0ac689a9867","url":"https://aisecwatch.com/issues/60ea1a9f-4810-4761-a4bd-c0ac689a9867","cveId":"CVE-2024-47167","title":"CVE-2024-47167: Gradio is an open-source Python package designed for quick prototyping. This vulnerability relates to **Server-Side…","headline":"Gradio server-side request forgery through the /queue/join endpoint","severity":"critical","publishedAt":"2024-10-11T02:15:11.000Z","affected":["gradio@< 5.0.0 (fixed: 5.0.0)"],"epssScore":0.00476,"matchedBy":"ecosystem"},{"id":"3fe71e63-cad3-4bfa-99e8-2cfd1297121a","url":"https://aisecwatch.com/issues/3fe71e63-cad3-4bfa-99e8-2cfd1297121a","cveId":"CVE-2024-47166","title":"CVE-2024-47166: Gradio is an open-source Python package designed for quick prototyping. This vulnerability involves a **one-level read…","headline":"Gradio one-level read path traversal in /custom_component endpoint","severity":"medium","publishedAt":"2024-10-11T02:15:10.833Z","affected":["gradio@< 4.44.0 (fixed: 4.44.0)"],"epssScore":0.00432,"matchedBy":"ecosystem"},{"id":"ac53d2d0-5ea7-47bd-b900-81d69ff4154c","url":"https://aisecwatch.com/issues/ac53d2d0-5ea7-47bd-b900-81d69ff4154c","cveId":"CVE-2024-47165","title":"CVE-2024-47165: Gradio is an open-source Python package designed for quick prototyping. This vulnerability relates to **CORS origin…","headline":"Gradio CORS origin validation accepts null origin on local deployments","severity":"medium","publishedAt":"2024-10-11T02:15:10.680Z","affected":["gradio@< 5.0.0 (fixed: 5.0.0)"],"epssScore":0.00298,"matchedBy":"ecosystem"},{"id":"f6494603-8755-432e-b36b-36336f71a297","url":"https://aisecwatch.com/issues/f6494603-8755-432e-b36b-36336f71a297","cveId":"CVE-2024-47164","title":"CVE-2024-47164: Gradio is an open-source Python package designed for quick prototyping. This vulnerability relates to the **bypass of…","headline":"Gradio directory traversal check bypass in is_in_or_equal function","severity":"medium","publishedAt":"2024-10-11T02:15:10.437Z","affected":["gradio@< 5.0.0 (fixed: 5.0.0)"],"epssScore":0.00705,"matchedBy":"ecosystem"},{"id":"e9c1f7a6-7d34-413c-ad38-49f238649dbd","url":"https://aisecwatch.com/issues/e9c1f7a6-7d34-413c-ad38-49f238649dbd","cveId":"CVE-2024-47084","title":"CVE-2024-47084: Gradio is an open-source Python package designed for quick prototyping. This vulnerability is related to **CORS origin…","headline":"Gradio CORS origin validation flaw allows cross-site requests","severity":"high","publishedAt":"2024-10-11T02:15:10.263Z","affected":["gradio@< 4.44.0 (fixed: 4.44.0)"],"epssScore":0.00532,"matchedBy":"ecosystem"},{"id":"6db58b6e-f466-4270-8860-48dfdf0fa926","url":"https://aisecwatch.com/issues/6db58b6e-f466-4270-8860-48dfdf0fa926","cveId":"CVE-2024-4940","title":"CVE-2024-4940: An open redirect vulnerability exists in the gradio-app/gradio, affecting the latest version. The vulnerability allows…","headline":"Gradio open redirect vulnerability via unvalidated URL input","severity":"medium","publishedAt":"2024-06-22T10:15:11.137Z","affected":["gradio@<= 4.36.1"],"epssScore":0.01021,"matchedBy":"ecosystem"},{"id":"8e8b358b-80ed-43b0-a427-5ea1212c0b47","url":"https://aisecwatch.com/issues/8e8b358b-80ed-43b0-a427-5ea1212c0b47","cveId":"CVE-2024-4941","title":"CVE-2024-4941: A local file inclusion vulnerability exists in the JSON component of gradio-app/gradio version 4.25. The vulnerability…","headline":"Gradio JSON component local file inclusion via postprocess","severity":"high","publishedAt":"2024-06-06T22:15:18.783Z","affected":["gradio@< 4.31.3 (fixed: 4.31.3)"],"epssScore":0.0083,"matchedBy":"ecosystem"},{"id":"c062185c-fcac-48e9-b7f5-31262589edd2","url":"https://aisecwatch.com/issues/c062185c-fcac-48e9-b7f5-31262589edd2","cveId":"CVE-2024-4325","title":"CVE-2024-4325: A Server-Side Request Forgery (SSRF) vulnerability exists in the gradio-app/gradio version 4.21.0, specifically within…","headline":"Gradio SSRF through the queue/join endpoint and save_url_to_cache","severity":"high","publishedAt":"2024-06-06T22:15:18.300Z","affected":["gradio@<= 4.36.0"],"epssScore":0.37114,"matchedBy":"ecosystem"},{"id":"fb43bc75-25c5-440c-90bb-85bd3c631977","url":"https://aisecwatch.com/issues/fb43bc75-25c5-440c-90bb-85bd3c631977","cveId":"CVE-2024-34510","title":"CVE-2024-34510: Gradio before 4.20 allows credential leakage on Windows.","headline":null,"severity":"high","publishedAt":"2024-05-06T00:15:07.417Z","affected":["gradio@< 4.20.0 (fixed: 4.20.0)"],"epssScore":0.00571,"matchedBy":"ecosystem"},{"id":"56b02279-06b2-41b5-8ca8-8fd5ce096507","url":"https://aisecwatch.com/issues/56b02279-06b2-41b5-8ca8-8fd5ce096507","cveId":"CVE-2024-1561","title":"CVE-2024-1561: An issue was discovered in gradio-app/gradio, where the `/component_server` endpoint improperly allows the invocation…","headline":"Gradio local file read through /component_server endpoint","severity":"high","publishedAt":"2024-04-16T04:15:08.887Z","affected":["gradio@< 4.13.0 (fixed: 4.13.0)"],"epssScore":0.09314,"matchedBy":"ecosystem"},{"id":"56bdfde9-c9db-44c8-abe0-9555d88446f2","url":"https://aisecwatch.com/issues/56bdfde9-c9db-44c8-abe0-9555d88446f2","cveId":"CVE-2024-1183","title":"CVE-2024-1183: An SSRF (Server-Side Request Forgery) vulnerability exists in the gradio-app/gradio repository, allowing attackers to…","headline":"Gradio SSRF through file parameter enabling internal port scanning","severity":"medium","publishedAt":"2024-04-16T04:15:07.990Z","affected":["gradio@< 4.10.0 (fixed: 4.10.0)"],"epssScore":0.01799,"matchedBy":"ecosystem"},{"id":"fc97834e-3537-4fc6-9ac7-61afed745449","url":"https://aisecwatch.com/issues/fc97834e-3537-4fc6-9ac7-61afed745449","cveId":"CVE-2024-1728","title":"CVE-2024-1728: gradio-app/gradio is vulnerable to a local file inclusion vulnerability due to improper validation of user-supplied…","headline":"gradio-app/gradio local file inclusion in UploadButton via /queue/join","severity":"high","publishedAt":"2024-04-10T21:15:53.097Z","affected":["gradio@< 4.19.2 (fixed: 4.19.2)"],"epssScore":0.85393,"matchedBy":"ecosystem"},{"id":"8567834c-8905-4fed-87fc-e7792eacb202","url":"https://aisecwatch.com/issues/8567834c-8905-4fed-87fc-e7792eacb202","cveId":"CVE-2024-1729","title":"CVE-2024-1729: A timing attack vulnerability exists in the gradio-app/gradio repository, specifically within the login function in…","headline":"Gradio timing attack in login function allows password guessing","severity":"high","publishedAt":"2024-03-29T09:15:45.477Z","affected":["gradio@< 4.19.2 (fixed: 4.19.2)"],"epssScore":0.00501,"matchedBy":"ecosystem"},{"id":"3b9c156c-1367-49d5-8bae-fe83010f4353","url":"https://aisecwatch.com/issues/3b9c156c-1367-49d5-8bae-fe83010f4353","cveId":"CVE-2024-2206","title":"CVE-2024-2206: An SSRF vulnerability exists in the gradio-app/gradio due to insufficient validation of user-supplied URLs in the…","headline":"gradio-app/gradio SSRF through the /proxy route via X-Direct-Url header","severity":"medium","publishedAt":"2024-03-27T05:15:46.613Z","affected":["gradio@< 4.18.0 (fixed: 4.18.0)"],"epssScore":0.00421,"matchedBy":"ecosystem"},{"id":"34526ec6-f5c8-4d2e-91b8-853e0ffbe5cb","url":"https://aisecwatch.com/issues/34526ec6-f5c8-4d2e-91b8-853e0ffbe5cb","cveId":"CVE-2024-1727","title":"CVE-2024-1727: A Cross-Site Request Forgery (CSRF) vulnerability in gradio-app/gradio allows attackers to upload multiple large files…","headline":"Gradio CSRF allows uploading large files to local systems","severity":"medium","publishedAt":"2024-03-22T00:15:07.620Z","affected":["gradio@< 4.19.2 (fixed: 4.19.2)"],"epssScore":0.00352,"matchedBy":"ecosystem"},{"id":"6c0c6579-9342-4255-81c3-ab94cbe9fea0","url":"https://aisecwatch.com/issues/6c0c6579-9342-4255-81c3-ab94cbe9fea0","cveId":"CVE-2024-0964","title":"CVE-2024-0964: A local file include could be remotely triggered in Gradio due to a vulnerable user-supplied JSON value in an API…","headline":"Gradio local file include through user-supplied JSON value in API request","severity":"critical","publishedAt":"2024-02-06T04:15:08.190Z","affected":["gradio@< 4.9.0 (fixed: 4.9.0)"],"epssScore":0.00959,"matchedBy":"ecosystem"},{"id":"49cd5562-9ee4-43b4-b8dc-da727e249844","url":"https://aisecwatch.com/issues/49cd5562-9ee4-43b4-b8dc-da727e249844","cveId":"CVE-2023-51449","title":"CVE-2023-51449: Gradio is an open-source Python package that allows you to quickly build a demo or web application for your machine…","headline":"Gradio file traversal through the /file route","severity":"medium","publishedAt":"2023-12-23T02:15:09.000Z","affected":["gradio@< 4.11.0 (fixed: 4.11.0)"],"epssScore":0.28336,"matchedBy":"ecosystem"},{"id":"1718cb40-71de-4556-a6e5-e11a565cae21","url":"https://aisecwatch.com/issues/1718cb40-71de-4556-a6e5-e11a565cae21","cveId":"CVE-2023-6572","title":"CVE-2023-6572: Command Injection in GitHub repository gradio-app/gradio prior to main.","headline":"gradio-app/gradio command injection","severity":"high","publishedAt":"2023-12-14T19:15:46.013Z","affected":["gradio@>= 0, < 4.14.0 (fixed: 4.14.0)"],"epssScore":0.01676,"matchedBy":"ecosystem"},{"id":"5c3534a1-440f-4a5c-9275-1e6c957d0567","url":"https://aisecwatch.com/issues/5c3534a1-440f-4a5c-9275-1e6c957d0567","cveId":"CVE-2023-41626","title":"CVE-2023-41626: Gradio v3.27.0 was discovered to contain an arbitrary file upload vulnerability via the /upload interface.","headline":"Gradio arbitrary file upload via the /upload interface","severity":"medium","publishedAt":"2023-09-16T03:15:07.370Z","affected":["gradio@<= 3.27.0"],"epssScore":0.00406,"matchedBy":"ecosystem"},{"id":"4e6fe1e1-cd3c-4909-ad3f-5b647ad1da22","url":"https://aisecwatch.com/issues/4e6fe1e1-cd3c-4909-ad3f-5b647ad1da22","cveId":"CVE-2023-34239","title":"CVE-2023-34239: Gradio is an open-source Python library that is used to build machine learning and data science. Due to a lack of path…","headline":"Gradio file access and URL proxying flaws due to missing path filtering","severity":"high","publishedAt":"2023-06-08T04:15:09.997Z","affected":["gradio@< 3.34.0 (fixed: 3.34.0)"],"epssScore":0.00651,"matchedBy":"ecosystem"},{"id":"e68e0042-5435-4761-8ccb-c2e5d276ceff","url":"https://aisecwatch.com/issues/e68e0042-5435-4761-8ccb-c2e5d276ceff","cveId":"CVE-2023-25823","title":"CVE-2023-25823: Gradio is an open-source Python library to build machine learning and data science demos and web applications. Versions…","headline":"Gradio hard-coded credentials exposure via share links","severity":"medium","publishedAt":"2023-02-24T03:15:11.580Z","affected":["gradio@< 3.13.1 (fixed: 3.13.1)"],"epssScore":0.00553,"matchedBy":"ecosystem"},{"id":"cb2a4c4e-510e-4f1e-87c0-1945ab4b4a72","url":"https://aisecwatch.com/issues/cb2a4c4e-510e-4f1e-87c0-1945ab4b4a72","cveId":"CVE-2022-24770","title":"CVE-2022-24770: `gradio` is an open source framework for building interactive machine learning models and demos. Prior to version…","headline":"gradio CSV injection in flagged output files","severity":"high","publishedAt":"2022-03-17T21:15:08.133Z","affected":["gradio@< 2.8.11 (fixed: 2.8.11)"],"epssScore":0.01298,"matchedBy":"ecosystem"},{"id":"72bbcfe1-7061-46c1-a18c-80b20549f51e","url":"https://aisecwatch.com/issues/72bbcfe1-7061-46c1-a18c-80b20549f51e","cveId":"CVE-2021-43831","title":"CVE-2021-43831: Gradio is an open source framework for building interactive machine learning models and demos. In versions prior to…","headline":"Gradio arbitrary file read through publicly shared interface links","severity":"high","publishedAt":"2021-12-16T01:15:08.620Z","affected":["gradio@< 2.5.0 (fixed: 2.5.0)"],"epssScore":0.03855,"matchedBy":"ecosystem"}],"checkedAt":"2026-10-09T21:57:17.245Z"},"meta":{"advisoryMatching":"by package name and ecosystem; an advisory with no ecosystem recorded for the package is matched by name alone"}}