VendorsGradio Projectgradioall versions
Vulnerabilities

Gradio Project Gradio

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

50CVEs
CVE-2024-8021
Open Redirect in gradio-app/gradio
Published 2025-03-20 · Analyzed
6.1EPSS 0.007
CVE-2024-1729
Timing Attack Vulnerability in gradio-app/gradio
Published 2024-03-29 · Analyzed
5.9EPSS 0.005
CVE-2026-27167
Gradio: Mocked OAuth Login Exposes Server Credentials and Uses Hardcoded Session Secret
Published 2026-02-27 · Analyzed
5.9EPSS 0.004
CVE-2024-47166
One-level read path traversal in `/custom_component` in Gradio
Published 2024-10-10 · Analyzed
5.3EPSS 0.004
CVE-2023-41626
Gradio v3.27.0 was discovered to contain an arbitrary file upload vulnerability via the /upload interface.
Published 2023-09-15 · Modified
4.8EPSS 0.004
CVE-2026-28415
Gradio has Open Redirect in OAuth Flow
Published 2026-02-27 · Analyzed
4.7EPSS 0.003
CVE-2024-1727
CSRF Vulnerability in gradio-app/gradio
Published 2024-03-21 · Analyzed
4.3EPSS 0.004
CVE-2024-47168
The `enable_monitoring` flag set to `False` does not disable monitoring in Gradio
Published 2024-10-10 · Analyzed
4.3EPSS 0.003
CVE-2024-47869
Non-constant-time comparison when comparing hashes in Gradio
Published 2024-10-10 · Analyzed
3.7EPSS 0.003
CVE-2026-10783
gradio-app gradio Audio Cache Key save_audio_to_cache weak hash
Published 2026-06-03 · Analyzed
2.5EPSS 0.001
← Prev2 / 2