{"id":"CVE-2024-1561","aliases":["GHSA-g9cj-cfpp-4g2x","PYSEC-2026-1415"],"title":"gradio vulnerable to Path Traversal","summary":"gradio vulnerable to Path Traversal","severity":"high","cvss":7.5,"cvssVector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","vendor":"gradio","product":"gradio","ecosystem":"pip","affected":["gradio < 4.13.0"],"patched":["gradio 4.13.0"],"published":"2024-04-16","updated":"2026-09-10","sourceUpdated":"2026-09-10T03:50:11.297187272Z","source":"OSV","sourceUrl":"https://osv.dev/vulnerability/GHSA-g9cj-cfpp-4g2x","references":[{"url":"https://nvd.nist.gov/vuln/detail/CVE-2024-1561"},{"url":"https://github.com/gradio-app/gradio/commit/24a583688046867ca8b8b02959c441818bdb34a2"},{"url":"https://github.com/gradio-app/gradio"},{"url":"https://huntr.com/bounties/4acf584e-2fe8-490e-878d-2d9bf2698338"},{"url":"https://www.gradio.app/changelog#4-13-0"}],"tags":["osv","pip","exploit-available"],"epss":0.09314,"epssPercentile":0.95211,"exploits":{"github":3,"githubRepos":["https://github.com/DiabloHTB/CVE-2024-1561","https://github.com/DiabloHTB/Nuclei-Template-CVE-2024-1561","https://github.com/K3ysTr0K3R/CVE-2024-1561"],"nuclei":["CVE-2024-1561"],"checkedAt":"2026-09-21T15:26:17.002Z"},"exploitAvailable":true,"ingestedAt":"2026-07-08T18:25:49.690Z","slug":"CVE-2024-1561","body":"## Overview\n\nAn issue was discovered in gradio-app/gradio, where the `/component_server` endpoint improperly allows the invocation of any method on a `Component` class with attacker-controlled arguments. Specifically, by exploiting the `move_resource_to_block_cache()` method of the `Block` class, an attacker can copy any file on the filesystem to a temporary directory and subsequently retrieve it. This vulnerability enables unauthorized local file read access, posing a significant risk especially when the application is exposed to the internet via `launch(share=True)`, thereby allowing remote attackers to read files on the host machine. Furthermore, gradio apps hosted on `huggingface.co` are also affected, potentially leading to the exposure of sensitive information such as API keys and credentials stored in environment variables.\n\n## Affected packages\n\n- `gradio < 4.13.0`\n\n## Remediation\n\nUpgrade to a patched release:\n\n- `gradio 4.13.0`","depth":"midnight","depthScore":55,"depthScoreParts":{"impact":41.3,"likelihood":1.9,"exploitation":12,"ransomware":0},"changes":[{"seq":4687,"id":"CVE-2024-1561","ts":1788887199765,"field":"exploit_available","old":"false","new":"true"},{"seq":3570,"id":"CVE-2024-1561","ts":1788886316261,"field":"exploit_available","old":"true","new":"false"},{"seq":2424,"id":"CVE-2024-1561","ts":1788882985025,"field":"exploit_available","old":"false","new":"true"},{"seq":1453,"id":"CVE-2024-1561","ts":1788882398296,"field":"exploit_available","old":"true","new":"false"},{"seq":567,"id":"CVE-2024-1561","ts":1788881834618,"field":"exploit_available","old":"false","new":"true"}]}