📦 Gradio

by Gradio Project

🔍 What is Gradio?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2024-47871

CRITICAL CVSS 9.1 Oct 10, 2024

This vulnerability allows attackers to intercept and read files uploaded to Gradio servers when using the share=True option, as HTTPS is not enforced. It affects users who publicly share Gradio demos ...

CVE-2024-47167

CRITICAL CVSS 9.8 Oct 10, 2024

This Server-Side Request Forgery (SSRF) vulnerability in Gradio allows attackers to force the server to make HTTP requests to arbitrary URLs, potentially accessing internal network resources or upload...

CVE-2024-0964

CRITICAL CVSS 9.4 Feb 5, 2024

CVE-2024-0964 is a critical local file inclusion vulnerability in Gradio that allows remote attackers to read arbitrary files on the server by exploiting a vulnerable user-supplied JSON value in API r...

CVE-2025-0187

HIGH CVSS 7.5 Mar 20, 2025

A Denial of Service vulnerability in gradio-app/gradio version 0.39.1 allows attackers to crash servers by uploading files with excessively long filenames. This affects any system running the vulnerab...

CVE-2025-23042

HIGH CVSS 7.5 Jan 14, 2025

This vulnerability allows attackers to bypass Gradio's file access controls by changing the letter case of blocked file paths on case-insensitive file systems. It affects Gradio users on Windows and m...

CVE-2024-47870

HIGH CVSS 8.1 Oct 10, 2024

A race condition in Gradio's update_root_in_config function allows attackers to redirect frontend-backend communication to malicious servers. This could intercept sensitive data like credentials or up...

CVE-2024-47867

HIGH CVSS 7.5 Oct 10, 2024

This vulnerability allows attackers to replace the FRP client binary with malicious code during download, as Gradio lacks integrity verification. Users who enable Gradio's sharing feature that downloa...

CVE-2024-47084

HIGH CVSS 8.3 Oct 10, 2024

This CVE allows malicious websites to bypass CORS origin validation in Gradio servers when cookies are present, enabling unauthorized requests to local Gradio instances. Attackers could potentially up...

CVE-2024-4325

HIGH CVSS 8.6 Jun 6, 2024

A Server-Side Request Forgery (SSRF) vulnerability in gradio-app/gradio version 4.21.0 allows attackers to make unauthorized HTTP requests from the vulnerable server. This could lead to access to inte...

CVE-2024-4941

HIGH CVSS 7.5 Jun 6, 2024

This CVE describes a local file inclusion vulnerability in gradio-app/gradio version 4.25. Attackers can exploit improper JSON parsing in the postprocess() function to read arbitrary files from the re...

CVE-2024-4254

HIGH CVSS 7.1 Jun 4, 2024

This CVE describes a GitHub Actions workflow vulnerability in the gradio repository that allows attackers to exfiltration sensitive secrets. The workflow improperly executes code from forks with eleva...

CVE-2024-34510

HIGH CVSS 7.5 May 5, 2024

Gradio versions before 4.20 on Windows systems may leak credentials stored in environment variables or configuration files. This affects any Windows user running vulnerable Gradio applications that ha...

CVE-2024-1561

HIGH CVSS 7.5 Apr 16, 2024

This vulnerability in gradio allows attackers to read any file on the filesystem by exploiting the /component_server endpoint. It affects gradio applications exposed to the internet via share=True and...

CVE-2024-1540

HIGH CVSS 8.2 Mar 27, 2024

A command injection vulnerability in the gradio-app/gradio repository's GitHub Actions workflow allows attackers to execute arbitrary commands by manipulating GitHub context variables. This affects or...

CVE-2023-6572

HIGH CVSS 8.1 Dec 14, 2023

This CVE describes a command injection vulnerability in the Gradio library that allows attackers to execute arbitrary commands on the host system. It affects applications using vulnerable versions of ...

CVE-2023-34239

HIGH CVSS 7.3 Jun 8, 2023

CVE-2023-34239 is a vulnerability in the Gradio Python library that allows attackers to access arbitrary files on the server and proxy requests to unauthorized URLs due to insufficient path and URL fi...

CVE-2024-8021

MEDIUM CVSS 6.1 Mar 20, 2025

An open redirect vulnerability in gradio-app/gradio allows attackers to redirect users to malicious websites using URL encoding. This affects all users of vulnerable gradio versions who interact with ...

CVE-2024-51751

MEDIUM CVSS 6.5 Nov 6, 2024

This vulnerability in Gradio allows attackers with access to the application to read arbitrary files from the server when using File or UploadButton components for file preview. All Gradio application...

CVE-2024-47165

MEDIUM CVSS 5.4 Oct 10, 2024

This CVE allows attackers to make unauthorized requests to locally deployed Gradio servers from sandboxed iframes or other sources with a null origin. This can lead to data theft including authenticat...