CVE-2021-43831High· 8.3▾ MidnightPoC availableFiles on the host computer can be accessed from the Gradio interface
▾ Midnight zone — Critical, or high with PoC / in-the-wild
impact 45.7 · likelihood 0.8 · exploitation 12
A public proof-of-concept already exists for this vulnerability — see Exploit availability below.
Public exploit / PoC code seen in 1 source. Availability, not in-the-wild use.
Exploit-prediction probability, daily snapshots since Jul 8.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via OSV
Last analysed / modified upstream
3.8%
Nuclei ×1
This is a vulnerability that affects anyone who creates and publicly shares Gradio interfaces using gradio<2.4.8. Because of the way that static files were being served, someone who generated a public Gradio link and shared it with others would potentially be exposing the files on the computer that generated the link, while the link was active. An attacker would be able to view the contents of a file on the computer if they knew the exact relative filepath. We do not have any evidence that this was ever exploited, but we treated the issue seriously and immediately took steps to mitigate it (see below)
gradio 2.5.0, within 24 hours of the issue being brought to our attentiongradio
The problem has been patched in gradio>=2.5.0.
gradio < 2.5.0Upgrade to a patched release:
gradio 2.5.0Field changes observed since this record was first indexed.
Connected by shared product, vendor, weakness, or advisory.
CVE-2023-6572Critical· 9.6Gradio Exposure of Sensitive Information to an Unauthorized Actor vulnerability
CVE-2023-51449High· 8.6Gradio makes the `/file` secure against file traversal and server-side request forgery attacks
CVE-2024-1183Medium· 6.5gradio Server-Side Request Forgery vulnerability
CVE-2024-1561High· 7.5gradio vulnerable to Path Traversal
CVE-2024-4940Medium· 5.4Open redirect in gradio
CVE-2024-4325High· 8.6Server-Side Request Forgery in gradio