Gradio < 6.7 on Windows with Python 3.13+ contains an absolute path traversal caused by incorrect path validation in path joining logic, letting unauthenticated attackers read arbitrary files from the server.
id: CVE-2026-28414
info:
name: Gradio - Absolute Path Traversal
author: 0x_Akoko
severity: hi
...