Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2024-1561 PoC — Arbitrary Local File Read via Component Method Invocation in gradio-app/gradio

Source
Associated Vulnerability
Title: Arbitrary Local File Read via Component Method Invocation in gradio-app/gradio (CVE-2024-1561)
Description:An issue was discovered in gradio-app/gradio, where the `/component_server` endpoint improperly allows the invocation of any method on a `Component` class with attacker-controlled arguments. Specifically, by exploiting the `move_resource_to_block_cache()` method of the `Block` class, an attacker can copy any file on the filesystem to a temporary directory and subsequently retrieve it. This vulnerability enables unauthorized local file read access, posing a significant risk especially when the application is exposed to the internet via `launch(share=True)`, thereby allowing remote attackers to read files on the host machine. Furthermore, gradio apps hosted on `huggingface.co` are also affected, potentially leading to the exposure of sensitive information such as API keys and credentials stored in environment variables.
Description
Poc for CVE-2024-1561 affecting Gradio 4.12.0
Readme
# CVE-2024-1561 PoC Script

This is a Proof of Concept (PoC) script for CVE-2024-1561.  

Check the full writeup for the CVE here: https://huntr.com/bounties/4acf584e-2fe8-490e-878d-2d9bf2698338

Affected Version: Gradio 4.12.0

This was fixed in this PR (https://github.com/gradio-app/gradio/pull/6884) and was released in version 4.13.0.

## Usage

1. Clone the repository and Navigate to the directory:

    ```bash
    git clone https://github.com/DiabloHTB/CVE-2024-1561
    cd CVE-2024-1561
    ```

2. Run the script with the following command:

    ```bash
    chmod +x CVE-2024-1561
    ./CVE-2024-1561 -u <URL> -f <FILE>
    ```

    Replace `<URL>` with the target URL and `<FILE>` with the file to be processed.

    Example:

    ```bash
    ./CVE-2024-1561 -u http://127.0.0.1:7860 -f /etc/passwd
    ```


## Options

- `-u, --url`: Specify the URL of the target.
- `-f, --file`: Specify the file.
- `-h, --help`: Help.

## Requirements

- Bash
- curl
- jq (for JSON parsing)

## Disclaimer

This script is a Proof of Concept (PoC) and should be used for educational and testing purposes only. Use it responsibly and at your own risk.


File Snapshot

Log in to view the POC file snapshot cached by Shenlong Bot

Log in to view
Remarks
    1. It is advised to access via the original source first.
    2. Local POC snapshots are reserved for subscribers — if the original source is unavailable, the local mirror is part of the paid plan.
    3. Mirroring, verifying, and maintaining this POC archive takes ongoing effort, so local snapshots are a paid feature. Your subscription keeps the archive online — thank you for the support. View subscription plans →