Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

gradio-app — Vulnerabilities & Security Advisories 50

Browse all 50 CVE security advisories affecting gradio-app. AI-powered Chinese analysis, POCs, and references for each vulnerability.

Gradio-app is an open-source Python library designed to simplify the creation of user interfaces for machine learning models, enabling developers to quickly demo and share AI applications. Despite its utility, the project has accumulated 46 recorded Common Vulnerabilities and Exposures (CVEs), reflecting significant security challenges in its rapid development cycle. Historically, these vulnerabilities frequently involve remote code execution (RCE) and cross-site scripting (XSS), often stemming from inadequate input sanitization or improper handling of uploaded files. While privilege escalation is less common, the potential for arbitrary code execution poses severe risks to deployment environments. Notable incidents highlight the dangers of exposing unverified model endpoints, emphasizing the need for rigorous security auditing. Users must implement strict access controls and keep dependencies updated to mitigate these inherent risks associated with the framework’s flexible architecture.

Top products by gradio-app: gradio gradio-app/gradio
CVE ID Title CVSS Severity Published
CVE-2026-59806 Gradio < 6.20.0 - Open Redirect and SSRF via /gradio_api/file= endpoint — gradio CWE-601 7.4 High 2026-07-08
CVE-2026-49119 Gradio < 6.16.0 Path Traversal via FileExplorer.preprocess() — gradio CWE-22 7.5 High 2026-07-01
CVE-2026-10783 gradio-app gradio Audio Cache Key save_audio_to_cache weak hash — gradio CWE-328 2.5 Low 2026-06-03
CVE-2026-48545 Gradio < 6.15.0 Cookie Injection via Shared Proxy Client — gradio CWE-384 6.8 Medium 2026-05-27
CVE-2026-28416 Gradio has SSRF via Malicious `proxy_url` Injection in `gr.load()` Config Processing — gradio CWE-918 8.2 High 2026-02-27
CVE-2026-28415 Gradio has Open Redirect in OAuth Flow — gradio CWE-200 4.3 Medium 2026-02-27
CVE-2026-28414 Gradio has Absolute Path Traversal on Windows with Python 3.13+ — gradio CWE-36 7.5 High 2026-02-27
CVE-2026-27167 Gradio: Mocked OAuth Login Exposes Server Credentials and Uses Hardcoded Session Secret — gradio CWE-798 - - 2026-02-27
CVE-2025-48889 Gradio Allows Unauthorized File Copy via Path Manipulation — gradio CWE-434 5.3 Medium 2025-05-30
CVE-2025-5320 gradio-app gradio CORS is_valid_origin privilege escalation — gradio CWE-346 3.7 Low 2025-05-29
CVE-2024-8021 Open Redirect in gradio-app/gradio — gradio-app/gradio CWE-601 6.1 - 2025-03-20
CVE-2024-10648 Path Traversal in gradio-app/gradio — gradio-app/gradio CWE-29 9.1 - 2025-03-20
CVE-2024-12217 Path Traversal in gradio-app/gradio — gradio-app/gradio CWE-22 3.3 - 2025-03-20
CVE-2024-8966 Denial of Service in gradio-app/gradio — gradio-app/gradio CWE-770 7.5 - 2025-03-20
CVE-2024-10569 Zip Bomb Vulnerability in gradio-app/gradio — gradio-app/gradio CWE-475 7.5 - 2025-03-20
CVE-2024-10624 Regular Expression Denial of Service (ReDoS) in gradio-app/gradio — gradio-app/gradio CWE-1333 7.5 - 2025-03-20
CVE-2025-0187 Denial of Service (DoS) by Sending Large Filename at File Upload Endpoint in gradio-app/gradio — gradio-app/gradio CWE-400 7.5 - 2025-03-20
CVE-2025-23042 Gradio Blocked Path ACL Bypass Vulnerability — gradio CWE-285 7.5 - 2025-01-14
CVE-2024-51751 Arbitrary file read with File and UploadButton components in Gradio — gradio CWE-22 6.5 Medium 2024-11-06
CVE-2024-47867 Lack of integrity check on the downloaded FRP client in Gradio — gradio CWE-345 8.8AI High AI 2024-10-10
CVE-2024-47868 Several components’ post-process steps may allow arbitrary file leaks in Gradio — gradio CWE-200 7.5AI High AI 2024-10-10
CVE-2024-47869 Non-constant-time comparison when comparing hashes in Gradio — gradio CWE-203 5.9AI Medium AI 2024-10-10
CVE-2024-47870 Race condition in update_root_in_config may redirect user traffic in Gradio — gradio CWE-362 5.8AI Medium AI 2024-10-10
CVE-2024-47871 Insecure communication between the FRP client and server in Gradio — gradio CWE-311 9.1AI Critical AI 2024-10-10
CVE-2024-47872 Cross-site Scripting on Gradio server via upload of HTML files, JS files, or SVG files — gradio CWE-79 5.4AI Medium AI 2024-10-10
CVE-2024-47084 CORS origin validation is not performed when the request has a cookie in Gradio — gradio CWE-285 8.1AI High AI 2024-10-10
CVE-2024-47164 The `is_in_or_equal` function may be bypassed in Gradio — gradio CWE-22 7.4AI High AI 2024-10-10
CVE-2024-47165 CORS origin validation accepts the null origin in Gradio — gradio CWE-285 6.2AI Medium AI 2024-10-10
CVE-2024-47166 One-level read path traversal in `/custom_component` in Gradio — gradio CWE-22 7.5AI High AI 2024-10-10
CVE-2024-47167 SSRF in the path parameter of /queue/join in Gradio — gradio CWE-918 9.8AI Critical AI 2024-10-10

This page lists every published CVE security advisory associated with gradio-app. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.