Gradio是Gradio开源的一个开源 Python 库,是通过友好的 Web 界面演示机器学习模型的方法。 Gradio 6.7之前版本存在安全漏洞,该漏洞源于Python 3.13+中os.path.isabs定义变更导致绝对路径遍历逻辑缺陷,可能导致未经验证的攻击者从文件系统读取任意文件。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| gradio-app | gradio | < 6.7 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|---|---|---|
| 1 | Gradio < 6.7 on Windows with Python 3.13+ contains an absolute path traversal caused by incorrect path validation in path joining logic, letting unauthenticated attackers read arbitrary files from the server. | https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2026/CVE-2026-28414.yaml | POC Details |
No public POC found.
Login to generate AI POC| CVE-2026-28416 | 8.2 HIGH | Gradio has SSRF via Malicious `proxy_url` Injection in `gr.load()` Config Processing |
| CVE-2026-28415 | 4.3 MEDIUM | Gradio has Open Redirect in OAuth Flow |
| CVE-2026-27167 | Gradio: Mocked OAuth Login Exposes Server Credentials and Uses Hardcoded Session Secret |
No comments yet