gradio vulnerabilities
CVEs whose affected-version data names the gradio package (pip). Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
27 CVEsRSS
CVE-2026-49119NoneGradio before 6.16.0 contain a path traversal vulnerability in the FileExplorer component's preprocess() method that allows unauthenticat…
Gradio before 6.16.0 contain a path traversal vulnerability in the FileExplorer component's preprocess() method that allows unauthenticated attackers to escape the configured root directory by supplying path segments containing directory…
CVE-2026-10783Low· 2.5Gradio: Audio cache key ignores metadata when saving numpy audio outputs
Gradio: Audio cache key ignores metadata when saving numpy audio outputs
CVE-2026-48545Medium· 6.8Gradio contains a cookie injection vulnerability
Gradio contains a cookie injection vulnerability
CVE-2025-5320Low· 3.7Gradio CORS Origin Validation Bypass Vulnerability
Gradio CORS Origin Validation Bypass Vulnerability
CVE-2024-10624High· 7.5Gradio Vulnerable to Denial of Service (DoS) via Crafted HTTP Request
Gradio Vulnerable to Denial of Service (DoS) via Crafted HTTP Request
CVE-2024-12217Medium· 5.3Gradio Path Traversal vulnerability
Gradio Path Traversal vulnerability
CVE-2024-10648High· 8.2Gradio Vulnerable to Arbitrary File Deletion
Gradio Vulnerable to Arbitrary File Deletion
CVE-2024-10569High· 7.5Gradio Vulnerable to Denial of Service (DoS) via Crafted Zip Bomb
Gradio Vulnerable to Denial of Service (DoS) via Crafted Zip Bomb
CVE-2024-8021Medium· 5.4PoCGradio Vulnerable to Open Redirect
Gradio Vulnerable to Open Redirect
CVE-2024-8966High· 7.5Gradio DOS in multipart boundry while uploading the file
Gradio DOS in multipart boundry while uploading the file
CVE-2024-48052Medium· 6.5gradio Server Side Request Forgery vulnerability
gradio Server Side Request Forgery vulnerability
GHSA-26jh-r8g2-6fprMedium· 5.3Gradio's dropdown component pre-process step does not limit the values to those in the dropdown list
Gradio's dropdown component pre-process step does not limit the values to those in the dropdown list
CVE-2024-4940Medium· 5.4PoCOpen redirect in gradio
Open redirect in gradio
CVE-2024-4325High· 8.6PoCServer-Side Request Forgery in gradio
Server-Side Request Forgery in gradio
CVE-2024-4253Critical· 9.1PoCA command injection vulnerability exists in the gradio-app/gradio repository, specifically within the 'test-functional.yml' workflow. The…
A command injection vulnerability exists in the gradio-app/gradio repository, specifically within the 'test-functional.yml' workflow. The vulnerability arises due to improper neutralization of special elements used in a command, allowing…
CVE-2024-1727Medium· 4.3Gradio applications running locally vulnerable to 3rd party websites accessing routes and uploading files
Gradio applications running locally vulnerable to 3rd party websites accessing routes and uploading files
CVE-2024-34511Medium· 6.5Gradio's Component Server does not properly consider` _is_server_fn` for functions
Gradio's Component Server does not properly consider` _is_server_fn` for functions
CVE-2024-1183Medium· 6.5PoCgradio Server-Side Request Forgery vulnerability
gradio Server-Side Request Forgery vulnerability
CVE-2024-1561High· 7.5PoCgradio vulnerable to Path Traversal
gradio vulnerable to Path Traversal
CVE-2024-2206High· 7.3gradio Server-Side Request Forgery vulnerability
gradio Server-Side Request Forgery vulnerability
CVE-2024-1729Medium· 5.9Gradio apps vulnerable to timing attacks to guess password
Gradio apps vulnerable to timing attacks to guess password
CVE-2023-51449High· 8.6PoCGradio makes the `/file` secure against file traversal and server-side request forgery attacks
Gradio makes the `/file` secure against file traversal and server-side request forgery attacks
CVE-2023-6572Critical· 9.6PoCGradio Exposure of Sensitive Information to an Unauthorized Actor vulnerability
Gradio Exposure of Sensitive Information to an Unauthorized Actor vulnerability
CVE-2023-41626Medium· 4.8Gradio arbitrary file upload vulnerability
Gradio arbitrary file upload vulnerability
CVE-2023-34239High· 7.3Gradio vulnerable to arbitrary file read and proxying of arbitrary URLs
Gradio vulnerable to arbitrary file read and proxying of arbitrary URLs
CVE-2023-25823Medium· 5.4Update share links to use FRP instead of SSH tunneling
Update share links to use FRP instead of SSH tunneling
CVE-2021-43831High· 8.3PoCFiles on the host computer can be accessed from the Gradio interface
Files on the host computer can be accessed from the Gradio interface