{"id":"CVE-2024-1183","aliases":["GHSA-qh6x-j82h-vpf9","PYSEC-2026-1419"],"title":"gradio Server-Side Request Forgery vulnerability","summary":"gradio Server-Side Request Forgery vulnerability","severity":"medium","cvss":6.5,"cvssVector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N","vendor":"gradio","product":"gradio","ecosystem":"pip","affected":["gradio < 4.10.0"],"patched":["gradio 4.10.0"],"published":"2024-04-16","updated":"2026-09-10","sourceUpdated":"2026-09-10T03:49:18.820680048Z","source":"OSV","sourceUrl":"https://osv.dev/vulnerability/GHSA-qh6x-j82h-vpf9","references":[{"url":"https://nvd.nist.gov/vuln/detail/CVE-2024-1183"},{"url":"https://github.com/gradio-app/gradio/commit/2ad3d9e7ec6c8eeea59774265b44f11df7394bb4"},{"url":"https://github.com/gradio-app/gradio/commit/7ba8c5da45b004edd12c0460be9222f5b5f5f055"},{"url":"https://github.com/gradio-app/gradio"},{"url":"https://huntr.com/bounties/103434f9-87d2-42ea-9907-194a3c25007c"}],"tags":["osv","pip","exploit-available"],"epss":0.01799,"epssPercentile":0.77177,"exploits":{"nuclei":["CVE-2024-1183"],"checkedAt":"2026-09-21T15:26:16.064Z"},"exploitAvailable":true,"ingestedAt":"2026-07-08T18:25:52.423Z","slug":"CVE-2024-1183","body":"## Overview\n\nAn SSRF (Server-Side Request Forgery) vulnerability exists in the gradio-app/gradio repository, allowing attackers to scan and identify open ports within an internal network. By manipulating the 'file' parameter in a GET request, an attacker can discern the status of internal ports based on the presence of a 'Location' header or a 'File not allowed' error in the response.\n\n## Affected packages\n\n- `gradio < 4.10.0`\n\n## Remediation\n\nUpgrade to a patched release:\n\n- `gradio 4.10.0`","depth":"twilight","depthScore":48,"depthScoreParts":{"impact":35.8,"likelihood":0.4,"exploitation":12,"ransomware":0},"changes":[{"seq":4684,"id":"CVE-2024-1183","ts":1788887199673,"field":"exploit_available","old":"false","new":"true"},{"seq":3567,"id":"CVE-2024-1183","ts":1788886316170,"field":"exploit_available","old":"true","new":"false"},{"seq":2421,"id":"CVE-2024-1183","ts":1788882984938,"field":"exploit_available","old":"false","new":"true"},{"seq":1450,"id":"CVE-2024-1183","ts":1788882398195,"field":"exploit_available","old":"true","new":"false"},{"seq":564,"id":"CVE-2024-1183","ts":1788881834524,"field":"exploit_available","old":"false","new":"true"}]}