VYPR

Gradio

by Gradio Project

Source repositories

CVEs (50)

  • CVE-2023-41626MedSep 15, 2023
    risk 0.31cvss 4.8epss 0.00

    Gradio v3.27.0 was discovered to contain an arbitrary file upload vulnerability via the /upload interface.

  • CVE-2024-47168MedOct 10, 2024
    risk 0.28cvss 4.3epss 0.00

    Gradio is an open-source Python package designed for quick prototyping. This vulnerability involves data exposure due to the enable_monitoring flag not properly disabling monitoring when set to False. Even when monitoring is supposedly disabled, an attacker or unauthorized user…

  • CVE-2025-48889MedMay 30, 2025
    risk 0.27cvss 5.3epss 0.01

    Gradio is an open-source Python package that allows quick building of demos and web application for machine learning models, API, or any arbitrary Python function. Prior to version 5.31.0, an arbitrary file copy vulnerability in Gradio's flagging feature allows unauthenticated…

  • CVE-2024-47869LowOct 10, 2024
    risk 0.24cvss 3.7epss 0.00

    Gradio is an open-source Python package designed for quick prototyping. This vulnerability involves a **timing attack** in the way Gradio compares hashes for the `analytics_dashboard` function. Since the comparison is not done in constant time, an attacker could exploit this by…

  • CVE-2026-28415MedFeb 27, 2026
    risk 0.21cvss 4.3epss 0.00

    Gradio is an open-source Python package designed for quick prototyping. Prior to version 6.6.0, the _redirect_to_target() function in Gradio's OAuth flow accepts an unvalidated _target_url query parameter, allowing redirection to arbitrary external URLs. This affects the /logout…

  • CVE-2024-1727MedMar 21, 2024
    risk 0.21cvss 4.3epss 0.00

    A Cross-Site Request Forgery (CSRF) vulnerability in gradio-app/gradio allows attackers to upload multiple large files to a victim's system if they are running Gradio locally. By crafting a malicious HTML page that triggers an unauthorized file upload to the victim's server, an…

  • CVE-2026-10783LowJun 4, 2026
    risk 0.09cvss 2.5epss 0.00

    A security flaw has been discovered in gradio-app gradio 6.14.0. This affects the function save_audio_to_cache of the component Audio Cache Key Handler. Performing a manipulation results in use of weak hash. The attack must be initiated from a local position. The attack is…

  • CVE-2026-49119HigJul 1, 2026
    risk 0.00cvss 7.5epss 0.01

    Gradio before 6.16.0 contain a path traversal vulnerability in the FileExplorer component's preprocess() method that allows unauthenticated attackers to escape the configured root directory by supplying path segments containing directory traversal sequences or absolute paths.…

  • CVE-2026-27167NonFeb 27, 2026
    risk 0.00cvss 0.0epss 0.00

    Gradio is an open-source Python package designed for quick prototyping. Starting in version 4.16.0 and prior to version 6.6.0, Gradio applications running outside of Hugging Face Spaces automatically enable "mocked" OAuth routes when OAuth components (e.g. `gr.LoginButton`) are…

  • CVE-2024-4253CriJun 4, 2024
    risk 0.00cvss 9.1epss 0.02

    A command injection vulnerability exists in the gradio-app/gradio repository, specifically within the 'test-functional.yml' workflow. The vulnerability arises due to improper neutralization of special elements used in a command, allowing for unauthorized modification of the base…

Page 3 of 3