Gradio是Hugging Face开源的一个开源 Python 库,是通过友好的 Web 界面演示机器学习模型的方法。 Gradio存在数据伪造问题漏洞,该漏洞源于如果攻击者获得下载 FRP 客户端的远程 URL 的访问权限,他们可以在不被发现的情况下修改二进制文件,因为 Gradio 服务器不会验证文件的校验和或签名。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| gradio-app | gradio | < 5.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2024-47166 | One-level read path traversal in `/custom_component` in Gradio | |
| CVE-2024-47872 | Cross-site Scripting on Gradio server via upload of HTML files, JS files, or SVG files | |
| CVE-2024-47165 | CORS origin validation accepts the null origin in Gradio | |
| CVE-2024-47167 | SSRF in the path parameter of /queue/join in Gradio | |
| CVE-2024-47168 | The `enable_monitoring` flag set to `False` does not disable monitoring in Gradio | |
| CVE-2024-47084 | CORS origin validation is not performed when the request has a cookie in Gradio | |
| CVE-2024-47870 | Race condition in update_root_in_config may redirect user traffic in Gradio | |
| CVE-2024-47871 | Insecure communication between the FRP client and server in Gradio | |
| CVE-2024-47164 | The `is_in_or_equal` function may be bypassed in Gradio | |
| CVE-2024-47869 | Non-constant-time comparison when comparing hashes in Gradio | |
| CVE-2024-47868 | Several components’ post-process steps may allow arbitrary file leaks in Gradio |
No comments yet