Newly released CVEs across every platform — sleek to read, verbose on demand, and served raw as markdown for AI and agent ingestion. Severity reads as depth: the deeper the contact, the graver the threat.
Depth = severity + exploitation
CVE-2026-49119NoneGradio before 6.16.0 contain a path traversal vulnerability in the FileExplorer component's preprocess() method that allows unauthenticated attackers to escape the configured root directory by supplying path segments containing directory…
CVE-2026-10783Low· 2.5Gradio: Audio cache key ignores metadata when saving numpy audio outputs
CVE-2026-48545Medium· 6.8Gradio contains a cookie injection vulnerability
CVE-2025-5320Low· 3.7Gradio CORS Origin Validation Bypass Vulnerability
CVE-2024-10624High· 7.5Gradio Vulnerable to Denial of Service (DoS) via Crafted HTTP Request
CVE-2024-12217Medium· 5.3Gradio Path Traversal vulnerability
CVE-2024-10648High· 8.2Gradio Vulnerable to Arbitrary File Deletion
CVE-2024-10569High· 7.5Gradio Vulnerable to Denial of Service (DoS) via Crafted Zip Bomb
CVE-2024-8021Medium· 5.4PoCGradio Vulnerable to Open Redirect
CVE-2024-8966High· 7.5Gradio DOS in multipart boundry while uploading the file
CVE-2024-48052Medium· 6.5gradio Server Side Request Forgery vulnerability
GHSA-26jh-r8g2-6fprMedium· 5.3Gradio's dropdown component pre-process step does not limit the values to those in the dropdown list
CVE-2024-4940Medium· 5.4PoCOpen redirect in gradio
CVE-2024-4325High· 8.6PoCServer-Side Request Forgery in gradio
CVE-2024-4253Critical· 9.1PoCA command injection vulnerability exists in the gradio-app/gradio repository, specifically within the 'test-functional.yml' workflow. The vulnerability arises due to improper neutralization of special elements used in a command, allowing…
CVE-2024-1727Medium· 4.3Gradio applications running locally vulnerable to 3rd party websites accessing routes and uploading files
CVE-2024-34511Medium· 6.5Gradio's Component Server does not properly consider` _is_server_fn` for functions
CVE-2024-1183Medium· 6.5PoCgradio Server-Side Request Forgery vulnerability
CVE-2024-1561High· 7.5PoCgradio vulnerable to Path Traversal
CVE-2024-2206High· 7.3gradio Server-Side Request Forgery vulnerability
CVE-2024-1729Medium· 5.9Gradio apps vulnerable to timing attacks to guess password
CVE-2023-51449High· 8.6PoCGradio makes the `/file` secure against file traversal and server-side request forgery attacks
CVE-2023-6572Critical· 9.6PoCGradio Exposure of Sensitive Information to an Unauthorized Actor vulnerability
CVE-2023-41626Medium· 4.8Gradio arbitrary file upload vulnerability
CVE-2023-34239High· 7.3Gradio vulnerable to arbitrary file read and proxying of arbitrary URLs
A summary of everything that shipped over the last two weeks — the whole corpus is open, agents get change feeds, alias resolution and EPSS movers, and the data now includes CVE.org, vendor CSAF, aggregated exploits and per-source scores.
A step-by-step guide to plugging VulnSea into automated and agentic workflows — poll the delta, triage without burning tokens, match an SBOM, and let an MCP-native model do the reasoning.
CVE and 0day intelligence that reads like an instrument — built for analysts and AI agents alike. Here's what it does and where it's going.