VulnSea

gradio vulnerabilities

CVEs whose affected-version data names the gradio package (pip). Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.

27 CVEsRSS

CVE-2026-49119None
2mo ago

Gradio before 6.16.0 contain a path traversal vulnerability in the FileExplorer component's preprocess() method that allows unauthenticat…

Gradio before 6.16.0 contain a path traversal vulnerability in the FileExplorer component's preprocess() method that allows unauthenticated attackers to escape the configured root directory by supplying path segments containing directory…

Sunlitgradio · gradioEPSS 0.93%via OSV
CVE-2026-10783Low· 2.5
3mo ago

Gradio: Audio cache key ignores metadata when saving numpy audio outputs

Gradio: Audio cache key ignores metadata when saving numpy audio outputs

Sunlitgradio · gradioEPSS 0.11%via OSV
CVE-2026-48545Medium· 6.8
3mo ago

Gradio contains a cookie injection vulnerability

Gradio contains a cookie injection vulnerability

Sunlitgradio · gradioEPSS 0.35%via OSV
CVE-2025-5320Low· 3.7
1y ago

Gradio CORS Origin Validation Bypass Vulnerability

Gradio CORS Origin Validation Bypass Vulnerability

Sunlitgradio · gradioEPSS 0.26%via OSV
CVE-2024-10624High· 7.5
1y ago

Gradio Vulnerable to Denial of Service (DoS) via Crafted HTTP Request

Gradio Vulnerable to Denial of Service (DoS) via Crafted HTTP Request

Twilightgradio · gradioEPSS 1.1%via OSV
CVE-2024-12217Medium· 5.3
1y ago

Gradio Path Traversal vulnerability

Gradio Path Traversal vulnerability

Sunlitgradio · gradioEPSS 0.69%via OSV
CVE-2024-10648High· 8.2
1y ago

Gradio Vulnerable to Arbitrary File Deletion

Gradio Vulnerable to Arbitrary File Deletion

Twilightgradio · gradioEPSS 0.72%via OSV
CVE-2024-10569High· 7.5
1y ago

Gradio Vulnerable to Denial of Service (DoS) via Crafted Zip Bomb

Gradio Vulnerable to Denial of Service (DoS) via Crafted Zip Bomb

Twilightgradio · gradioEPSS 0.65%via OSV
CVE-2024-8021Medium· 5.4PoC
1y ago

Gradio Vulnerable to Open Redirect

Gradio Vulnerable to Open Redirect

Twilightgradio · gradioEPSS 0.74%via OSV
CVE-2024-8966High· 7.5
1y ago

Gradio DOS in multipart boundry while uploading the file

Gradio DOS in multipart boundry while uploading the file

Twilightgradio · gradioEPSS 0.79%via OSV
CVE-2024-48052Medium· 6.5
1y ago

gradio Server Side Request Forgery vulnerability

gradio Server Side Request Forgery vulnerability

Sunlitgradio · gradioEPSS 0.47%via OSV
GHSA-26jh-r8g2-6fprMedium· 5.3
1y ago

Gradio's dropdown component pre-process step does not limit the values to those in the dropdown list

Gradio's dropdown component pre-process step does not limit the values to those in the dropdown list

Sunlitgradio · gradiovia OSV
CVE-2024-4940Medium· 5.4PoC
2y ago

Open redirect in gradio

Open redirect in gradio

Twilightgradio · gradioEPSS 1.0%via OSV
CVE-2024-4325High· 8.6PoC
2y ago

Server-Side Request Forgery in gradio

Server-Side Request Forgery in gradio

Midnightgradio · gradioEPSS 37%via OSV
CVE-2024-4253Critical· 9.1PoC
2y ago

A command injection vulnerability exists in the gradio-app/gradio repository, specifically within the 'test-functional.yml' workflow. The…

A command injection vulnerability exists in the gradio-app/gradio repository, specifically within the 'test-functional.yml' workflow. The vulnerability arises due to improper neutralization of special elements used in a command, allowing…

Abyssalgradio · gradioEPSS 1.7%via OSV
CVE-2024-1727Medium· 4.3
2y ago

Gradio applications running locally vulnerable to 3rd party websites accessing routes and uploading files

Gradio applications running locally vulnerable to 3rd party websites accessing routes and uploading files

Sunlitgradio · gradioEPSS 0.35%via OSV
CVE-2024-34511Medium· 6.5
2y ago

Gradio's Component Server does not properly consider` _is_server_fn` for functions

Gradio's Component Server does not properly consider` _is_server_fn` for functions

Sunlitgradio · gradiovia OSV
CVE-2024-1183Medium· 6.5PoC
2y ago

gradio Server-Side Request Forgery vulnerability

gradio Server-Side Request Forgery vulnerability

Twilightgradio · gradioEPSS 1.8%via OSV
CVE-2024-1561High· 7.5PoC
2y ago

gradio vulnerable to Path Traversal

gradio vulnerable to Path Traversal

Midnightgradio · gradioEPSS 9.3%via OSV
CVE-2024-2206High· 7.3
2y ago

gradio Server-Side Request Forgery vulnerability

gradio Server-Side Request Forgery vulnerability

Twilightgradio · gradioEPSS 0.42%via OSV
CVE-2024-1729Medium· 5.9
2y ago

Gradio apps vulnerable to timing attacks to guess password

Gradio apps vulnerable to timing attacks to guess password

Sunlitgradio · gradioEPSS 0.50%via OSV
CVE-2023-51449High· 8.6PoC
2y ago

Gradio makes the `/file` secure against file traversal and server-side request forgery attacks

Gradio makes the `/file` secure against file traversal and server-side request forgery attacks

Midnightgradio · gradioEPSS 28%via OSV
CVE-2023-6572Critical· 9.6PoC
2y ago

Gradio Exposure of Sensitive Information to an Unauthorized Actor vulnerability

Gradio Exposure of Sensitive Information to an Unauthorized Actor vulnerability

Abyssalgradio · gradioEPSS 1.7%via OSV
CVE-2023-41626Medium· 4.8
3y ago

Gradio arbitrary file upload vulnerability

Gradio arbitrary file upload vulnerability

Sunlitgradio · gradioEPSS 0.41%via OSV
CVE-2023-34239High· 7.3
3y ago

Gradio vulnerable to arbitrary file read and proxying of arbitrary URLs

Gradio vulnerable to arbitrary file read and proxying of arbitrary URLs

Twilightgradio · gradioEPSS 0.65%via OSV
CVE-2023-25823Medium· 5.4
3y ago

Update share links to use FRP instead of SSH tunneling

Update share links to use FRP instead of SSH tunneling

Sunlitgradio · gradioEPSS 0.55%via OSV
CVE-2021-43831High· 8.3PoC
4y ago

Files on the host computer can be accessed from the Gradio interface

Files on the host computer can be accessed from the Gradio interface

Midnightgradio · gradioEPSS 3.8%via OSV
gradio vulnerabilities (CVEs) · VulnSea