{"id":"CVE-2023-6572","aliases":["GHSA-gqvf-3hgp-5hxv","PYSEC-2023-255"],"title":"Gradio Exposure of Sensitive Information to an Unauthorized Actor vulnerability","summary":"Gradio Exposure of Sensitive Information to an Unauthorized Actor vulnerability","severity":"critical","cvss":9.6,"cvssVector":"CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N","vendor":"gradio","product":"gradio","ecosystem":"pip","affected":["gradio < 4.14.0"],"patched":["gradio 4.14.0"],"published":"2023-12-14","updated":"2026-09-10","sourceUpdated":"2026-09-10T03:50:04.404930854Z","source":"OSV","sourceUrl":"https://osv.dev/vulnerability/GHSA-gqvf-3hgp-5hxv","references":[{"url":"https://nvd.nist.gov/vuln/detail/CVE-2023-6572"},{"url":"https://github.com/gradio-app/gradio/commit/5b5af1899dd98d63e1f9b48a93601c2db1f56520"},{"url":"https://github.com/gradio-app/gradio"},{"url":"https://github.com/pypa/advisory-database/tree/main/vulns/gradio/PYSEC-2023-255.yaml"},{"url":"https://huntr.com/bounties/21d2ff0c-d43a-4afd-bb4d-049ee8da5b5c"}],"tags":["osv","pip","exploit-available"],"epss":0.01724,"epssPercentile":0.76196,"exploits":{"github":1,"githubRepos":["https://github.com/pvharmo2/gha-lab-6255f5fc33"],"checkedAt":"2026-09-21T15:26:02.923Z"},"exploitAvailable":true,"ingestedAt":"2026-09-12T03:13:01.697Z","slug":"CVE-2023-6572","body":"## Overview\n\nExposure of Sensitive Information to an Unauthorized Actor in GitHub repository gradio-app/gradio prior to main.\n\n## Affected packages\n\n- `gradio < 4.14.0`\n\n## Remediation\n\nUpgrade to a patched release:\n\n- `gradio 4.14.0`","depth":"abyssal","depthScore":65,"depthScoreParts":{"impact":52.8,"likelihood":0.3,"exploitation":12,"ransomware":0},"changes":[]}