Gradio Project
Gradio Project Gradio: vulnerabilidades y CVE
Gradio Project Gradio tiene 50 vulnerabilidades publicadas, 7 de ellas en los últimos 12 meses. 5 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE50
Últimos 12 meses7
Críticas5
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-49119 | Alta (8.7) | 0.93% | — | 1 jul 2026 | Gradio before 6.16.0 contain a path traversal vulnerability in the FileExplorer component's preprocess() method that allows unauthenticated attackers to escape the configured root directory by supplying path segments… |
| CVE-2026-10783 | Baja (1.1) | 0.11% | — | 4 jun 2026 | A security flaw has been discovered in gradio-app gradio 6.14.0. This affects the function save_audio_to_cache of the component Audio Cache Key Handler. Performing a manipulation results in use of weak hash. The attack… |
| CVE-2026-48545 | Alta (7.6) | 0.47% | — | 27 may 2026 | Gradio before version 6.15.0 contains a cookie injection vulnerability that allows remote attackers to perform cross-Space session fixation by exploiting a shared module-level HTTP client used across all users in the… |
| CVE-2026-28416 | Alta (8.6) | 0.35% | — | 27 feb 2026 | Gradio is an open-source Python package designed for quick prototyping. Prior to version 6.6.0, a Server-Side Request Forgery (SSRF) vulnerability in Gradio allows an attacker to make arbitrary HTTP requests from a… |
| CVE-2026-28415 | Media (4.7) | 0.29% | — | 27 feb 2026 | Gradio is an open-source Python package designed for quick prototyping. Prior to version 6.6.0, the _redirect_to_target() function in Gradio's OAuth flow accepts an unvalidated _target_url query parameter, allowing… |
| CVE-2026-28414 | Alta (7.5) | 2.5% | — | 27 feb 2026 | Gradio is an open-source Python package designed for quick prototyping. Prior to version 6.7, Gradio apps running on Window with Python 3.13+ are vulnerable to an absolute path traversal issue that enables… |
| CVE-2026-27167 | Media (5.9) | 0.39% | — | 27 feb 2026 | Gradio is an open-source Python package designed for quick prototyping. Starting in version 4.16.0 and prior to version 6.6.0, Gradio applications running outside of Hugging Face Spaces automatically enable "mocked"… |
| CVE-2025-48889 | Alta (7.5) | 0.66% | — | 30 may 2025 | Gradio is an open-source Python package that allows quick building of demos and web application for machine learning models, API, or any arbitrary Python function. Prior to version 5.31.0, an arbitrary file copy… |
| CVE-2025-0187 | Alta (7.5) | 0.72% | — | 20 mar 2025 | A Denial of Service (DoS) vulnerability was discovered in the file upload feature of gradio-app/gradio version 0.39.1. The vulnerability is due to improper handling of form-data with a large filename in the file upload… |
| CVE-2024-8021 | Media (6.1) | 0.74% | — | 20 mar 2025 | An open redirect vulnerability exists in the latest version of gradio-app/gradio. The vulnerability allows an attacker to redirect users to a malicious website by URL encoding. This can be exploited by sending a crafted… |
| CVE-2024-10648 | Alta (8.2) | 0.72% | — | 20 mar 2025 | A path traversal vulnerability exists in the Gradio Audio component of gradio-app/gradio, as of version git 98cbcae. This vulnerability allows an attacker to control the format of the audio file, leading to arbitrary… |
| CVE-2024-10624 | Alta (7.5) | 1.1% | — | 20 mar 2025 | A Regular Expression Denial of Service (ReDoS) vulnerability exists in the gradio-app/gradio repository, affecting the gr.Datetime component. The affected version is git commit 98cbcae. The vulnerability arises from the… |
| CVE-2024-10569 | Alta (7.5) | 0.65% | — | 20 mar 2025 | A vulnerability in the dataframe component of gradio-app/gradio (version git 98cbcae) allows for a zip bomb attack. The component uses pd.read_csv to process input values, which can accept compressed files. An attacker… |
| CVE-2025-23042 | Alta (8.7) | 0.98% | — | 14 ene 2025 | Gradio is an open-source Python package that allows quick building of demos and web application for machine learning models, API, or any arbitrary Python function. Gradio's Access Control List (ACL) for file paths can… |
| CVE-2024-51751 | Media (6.5) | 0.69% | — | 6 nov 2024 | Gradio is an open-source Python package designed to enable quick builds of a demo or web application. If File or UploadButton components are used as a part of Gradio application to preview file content, an attacker with… |
| CVE-2024-48052 | Media (6.5) | 0.47% | — | 4 nov 2024 | In gradio <=4.42.0, the gr.DownloadButton function has a hidden server-side request forgery (SSRF) vulnerability. The reason is that within the save_url_to_cache function, there are no restrictions on the URL, which… |
| CVE-2024-47872 | Media (6.9) | 0.27% | — | 10 oct 2024 | Gradio is an open-source Python package designed for quick prototyping. This vulnerability involves **Cross-Site Scripting (XSS)** on any Gradio server that allows file uploads. Authenticated users can upload files such… |
| CVE-2024-47871 | Alta (8.2) | 0.18% | — | 10 oct 2024 | Gradio is an open-source Python package designed for quick prototyping. This vulnerability involves **insecure communication** between the FRP (Fast Reverse Proxy) client and server when Gradio's `share=True` option is… |
| CVE-2024-47870 | Alta (7.1) | 0.37% | — | 10 oct 2024 | Gradio is an open-source Python package designed for quick prototyping. This vulnerability involves a **race condition** in the `update_root_in_config` function, allowing an attacker to modify the `root` URL used by the… |
| CVE-2024-47869 | Baja (2.3) | 0.29% | — | 10 oct 2024 | Gradio is an open-source Python package designed for quick prototyping. This vulnerability involves a **timing attack** in the way Gradio compares hashes for the `analytics_dashboard` function. Since the comparison is… |
| CVE-2024-47868 | Media (6.3) | 0.81% | — | 10 oct 2024 | Gradio is an open-source Python package designed for quick prototyping. This is a **data validation vulnerability** affecting several Gradio components, which allows arbitrary file leaks through the post-processing… |
| CVE-2024-47867 | Baja (2.1) | 0.21% | — | 10 oct 2024 | Gradio is an open-source Python package designed for quick prototyping. This vulnerability is a **lack of integrity check** on the downloaded FRP client, which could potentially allow attackers to introduce malicious… |
| CVE-2024-47168 | Baja (2.3) | 0.33% | — | 10 oct 2024 | Gradio is an open-source Python package designed for quick prototyping. This vulnerability involves data exposure due to the enable_monitoring flag not properly disabling monitoring when set to False. Even when… |
| CVE-2024-47167 | Media (6.9) | 0.48% | — | 10 oct 2024 | Gradio is an open-source Python package designed for quick prototyping. This vulnerability relates to **Server-Side Request Forgery (SSRF)** in the `/queue/join` endpoint. Gradio’s `async_save_url_to_cache` function… |
| CVE-2024-47166 | Baja (2.3) | 0.43% | — | 10 oct 2024 | Gradio is an open-source Python package designed for quick prototyping. This vulnerability involves a **one-level read path traversal** in the `/custom_component` endpoint. Attackers can exploit this flaw to access and… |
| CVE-2024-47165 | Media (6.9) | 0.30% | — | 10 oct 2024 | Gradio is an open-source Python package designed for quick prototyping. This vulnerability relates to **CORS origin validation accepting a null origin**. When a Gradio server is deployed locally, the `localhost_aliases`… |
| CVE-2024-47164 | Baja (2.3) | 0.70% | — | 10 oct 2024 | Gradio is an open-source Python package designed for quick prototyping. This vulnerability relates to the **bypass of directory traversal checks** within the `is_in_or_equal` function. This function, intended to check… |
| CVE-2024-47084 | Media (6.9) | 0.53% | — | 10 oct 2024 | Gradio is an open-source Python package designed for quick prototyping. This vulnerability is related to **CORS origin validation**, where the Gradio server fails to validate the request origin when a cookie is present.… |
| CVE-2024-39236 | Crítica (9.8) | 0.87% | — | 1 jul 2024 | Gradio v4.36.1 was discovered to contain a code injection vulnerability via the component /gradio/component_meta.py. This vulnerability is triggered via a crafted input. NOTE: the supplier disputes this because the… |
| CVE-2024-4940 | Media (6.1) | 1.0% | — | 22 jun 2024 | An open redirect vulnerability exists in the gradio-app/gradio, affecting the latest version. The vulnerability allows an attacker to redirect users to arbitrary websites, which can be exploited for phishing attacks,… |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.