VendorsGradio Projectgradioall versions
Vulnerabilities

Gradio Project Gradio

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

50CVEs
CVE-2024-39236
Gradio v4.36.1 was discovered to contain a code injection vulnerability via the component /gradio/component_meta.py. This vulnerability is triggered via a crafted input. NOTE: the supplier disputes this because the report is about a user attacking himself.
Published 2024-07-01 · Analyzed
9.8EPSS 0.009
CVE-2023-25823
Gradio contains Use of Hard-coded Credentials
Published 2023-02-23 · Modified
9.8EPSS 0.006
CVE-2024-47167
SSRF in the path parameter of /queue/join in Gradio
Published 2024-10-10 · Analyzed
9.8EPSS 0.005
CVE-2023-6572
Command Injection in gradio-app/gradio
Published 2023-12-14 · Modified
9.6EPSS 0.017
CVE-2024-0964
LFI in Gradio
Published 2024-02-05 · Modified
9.4EPSS 0.010
CVE-2024-4253
Command Injection in gradio-app/gradio
Published 2024-06-04 · Modified
9.1EPSS 0.017
CVE-2023-34239
Unfiltered paths in gradio
Published 2023-06-07 · Modified
9.1EPSS 0.007
CVE-2024-47871
Insecure communication between the FRP client and server in Gradio
Published 2024-10-10 · Analyzed
9.1EPSS 0.002
CVE-2022-24770
Improper Neutralization of Formula Elements in a CSV File in Gradio Flagging
Published 2022-03-17 · Modified
8.8EPSS 0.013
CVE-2025-23042
Gradio Blocked Path ACL Bypass Vulnerability
Published 2025-01-14 · Analyzed
8.7EPSS 0.010
CVE-2026-49119
Gradio < 6.16.0 Path Traversal via FileExplorer.preprocess()
Published 2026-07-01 · Analyzed
8.7EPSS 0.009
CVE-2024-4325
Server-Side Request Forgery (SSRF) in gradio-app/gradio
Published 2024-06-06 · Modified
8.6EPSS 0.374
CVE-2024-1540
Command Injection in gradio-app/gradio via deploy+test-visual.yml workflow
Published 2024-03-27 · Analyzed
8.6EPSS 0.020
CVE-2026-28416
Gradio has SSRF via Malicious `proxy_url` Injection in `gr.load()` Config Processing
Published 2026-02-27 · Analyzed
8.6EPSS 0.003
CVE-2024-47084
CORS origin validation is not performed when the request has a cookie in Gradio
Published 2024-10-10 · Analyzed
8.3EPSS 0.005
CVE-2024-10648
Path Traversal in gradio-app/gradio
Published 2025-03-20 · Analyzed
8.2EPSS 0.007
CVE-2024-47870
Race condition in update_root_in_config may redirect user traffic in Gradio
Published 2024-10-10 · Analyzed
8.1EPSS 0.004
CVE-2021-43831
Files on the host computer can be accessed from the Gradio interface
Published 2021-12-15 · Modified
7.7EPSS 0.038
CVE-2026-48545
Gradio < 6.15.0 Cookie Injection via Shared Proxy Client
Published 2026-05-27 · Analyzed
7.6EPSS 0.005
CVE-2024-1728
Local File Inclusion in gradio-app/gradio
Published 2024-04-10 · Analyzed
7.5EPSS 0.854
CVE-2023-51449
Make the `/file` secure against file traversal attacks
Published 2023-12-22 · Modified
7.5EPSS 0.283
CVE-2024-1561
Arbitrary Local File Read via Component Method Invocation in gradio-app/gradio
Published 2024-04-16 · Analyzed
7.5EPSS 0.093
CVE-2026-28414
Gradio has Absolute Path Traversal on Windows with Python 3.13+
Published 2026-02-27 · Analyzed
7.5EPSS 0.025
CVE-2024-10624
Regular Expression Denial of Service (ReDoS) in gradio-app/gradio
Published 2025-03-20 · Modified
7.5EPSS 0.011
CVE-2024-4941
Local File Inclusion in JSON component in gradio-app/gradio
Published 2024-06-06 · Modified
7.5EPSS 0.008
CVE-2024-47868
Several components’ post-process steps may allow arbitrary file leaks in Gradio
Published 2024-10-10 · Analyzed
7.5EPSS 0.008
CVE-2025-0187
Denial of Service (DoS) by Sending Large Filename at File Upload Endpoint in gradio-app/gradio
Published 2025-03-20 · Analyzed
7.5EPSS 0.007
CVE-2025-48889
Gradio Allows Unauthorized File Copy via Path Manipulation
Published 2025-05-30 · Analyzed
7.5EPSS 0.007
CVE-2024-10569
Zip Bomb Vulnerability in gradio-app/gradio
Published 2025-03-20 · Analyzed
7.5EPSS 0.006
CVE-2024-34510
Gradio before 4.20 allows credential leakage on Windows.
Published 2024-05-05 · Analyzed
7.5EPSS 0.006
CVE-2024-47867
Lack of integrity check on the downloaded FRP client in Gradio
Published 2024-10-10 · Analyzed
7.5EPSS 0.002
CVE-2024-2206
SSRF Vulnerability in gradio-app/gradio
Published 2024-03-27 · Analyzed
7.3EPSS 0.004
CVE-2024-4254
Secrets Exfiltration in gradio-app/gradio
Published 2024-06-04 · Modified
7.1EPSS 0.005
CVE-2024-47165
CORS origin validation accepts the null origin in Gradio
Published 2024-10-10 · Analyzed
6.9EPSS 0.003
CVE-2024-47872
Cross-site Scripting on Gradio server via upload of HTML files, JS files, or SVG files
Published 2024-10-10 · Analyzed
6.9EPSS 0.003
CVE-2024-1183
SSRF Vulnerability in gradio-app/gradio
Published 2024-04-16 · Analyzed
6.5EPSS 0.018
CVE-2024-47164
The `is_in_or_equal` function may be bypassed in Gradio
Published 2024-10-10 · Analyzed
6.5EPSS 0.007
CVE-2024-51751
Arbitrary file read with File and UploadButton components in Gradio
Published 2024-11-06 · Analyzed
6.5EPSS 0.007
CVE-2024-48052
In gradio <=4.42.0, the gr.DownloadButton function has a hidden server-side request forgery (SSRF) vulnerability. The reason is that within the save_url_to_cache function, there are no restrictions on the URL, which allows access to local target resources. This can lead to the download of local resources and sensitive information.
Published 2024-11-04 · Analyzed
6.5EPSS 0.005
CVE-2024-4940
Open Redirect in gradio-app/gradio
Published 2024-06-22 · Analyzed
6.1EPSS 0.010
1 / 2Next →