---
id: CVE-2023-6572
aliases:
  - GHSA-gqvf-3hgp-5hxv
  - PYSEC-2023-255
title: >-
  Gradio Exposure of Sensitive Information to an Unauthorized Actor
  vulnerability
summary: >-
  Gradio Exposure of Sensitive Information to an Unauthorized Actor
  vulnerability
severity: critical
cvss: 9.6
cvssVector: 'CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N'
vendor: gradio
product: gradio
ecosystem: pip
affected:
  - gradio < 4.14.0
patched:
  - gradio 4.14.0
published: '2023-12-14'
updated: '2026-09-10'
sourceUpdated: '2026-09-10T03:50:04.404930854Z'
source: OSV
sourceUrl: 'https://osv.dev/vulnerability/GHSA-gqvf-3hgp-5hxv'
references:
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2023-6572'
  - url: >-
      https://github.com/gradio-app/gradio/commit/5b5af1899dd98d63e1f9b48a93601c2db1f56520
  - url: 'https://github.com/gradio-app/gradio'
  - url: >-
      https://github.com/pypa/advisory-database/tree/main/vulns/gradio/PYSEC-2023-255.yaml
  - url: 'https://huntr.com/bounties/21d2ff0c-d43a-4afd-bb4d-049ee8da5b5c'
tags:
  - osv
  - pip
  - exploit-available
epss: 0.01724
epssPercentile: 0.76522
exploits:
  github: 1
  githubRepos:
    - 'https://github.com/pvharmo2/gha-lab-6255f5fc33'
  checkedAt: '2026-09-23T07:13:26.423Z'
exploitAvailable: true
ingestedAt: '2026-09-12T03:13:01.697Z'
---

## Overview

Exposure of Sensitive Information to an Unauthorized Actor in GitHub repository gradio-app/gradio prior to main.

## Affected packages

- `gradio < 4.14.0`

## Remediation

Upgrade to a patched release:

- `gradio 4.14.0`
