gradio has 27 CVEs on record between 2022 and 2026. 1 was published in the last 90 days. The median CVSS is 6.7 (medium), with 2 rated critical. None have a confirmed exploitation report.
CVEs per month
Last 12 months, by publish date
- Exploited share
- 0% vs 1% corpus
- Median CVSS
- 6.7
- Publish → KEV
- —
- Last 90 days
- 1 prev 2
Products
- gradio 27
Worst active — by depth score
CVE-2024-4325High· 8.6Server-Side Request Forgery in gradio67CVE-2023-51449High· 8.6Gradio makes the `/file` secure against file traversal and server-side request forgery attacks65CVE-2023-6572Critical· 9.6Gradio Exposure of Sensitive Information to an Unauthorized Actor vulnerability65CVE-2024-4253Critical· 9.1A command injection vulnerability exists in the gradio-app/gradio repository, specifically within the 'test-functional.yml' workflow. The…62CVE-2021-43831High· 8.3Files on the host computer can be accessed from the Gradio interface58
gradio vulnerabilities
CVEs affecting gradio, newest first. Open any entry for full detail, references, and exploit status.
27 CVEsRSS
CVE-2026-49119NoneGradio before 6.16.0 contain a path traversal vulnerability in the FileExplorer component's preprocess() method that allows unauthenticat…
Gradio before 6.16.0 contain a path traversal vulnerability in the FileExplorer component's preprocess() method that allows unauthenticated attackers to escape the configured root directory by supplying path segments containing directory…
CVE-2026-10783Low· 2.5Gradio: Audio cache key ignores metadata when saving numpy audio outputs
Gradio: Audio cache key ignores metadata when saving numpy audio outputs
CVE-2026-48545Medium· 6.8Gradio contains a cookie injection vulnerability
Gradio contains a cookie injection vulnerability
CVE-2025-5320Low· 3.7Gradio CORS Origin Validation Bypass Vulnerability
Gradio CORS Origin Validation Bypass Vulnerability
CVE-2024-10624High· 7.5Gradio Vulnerable to Denial of Service (DoS) via Crafted HTTP Request
Gradio Vulnerable to Denial of Service (DoS) via Crafted HTTP Request
CVE-2024-12217Medium· 5.3Gradio Path Traversal vulnerability
Gradio Path Traversal vulnerability
CVE-2024-10648High· 8.2Gradio Vulnerable to Arbitrary File Deletion
Gradio Vulnerable to Arbitrary File Deletion
CVE-2024-10569High· 7.5Gradio Vulnerable to Denial of Service (DoS) via Crafted Zip Bomb
Gradio Vulnerable to Denial of Service (DoS) via Crafted Zip Bomb
CVE-2024-8021Medium· 5.4PoCGradio Vulnerable to Open Redirect
Gradio Vulnerable to Open Redirect
CVE-2024-8966High· 7.5Gradio DOS in multipart boundry while uploading the file
Gradio DOS in multipart boundry while uploading the file
CVE-2024-48052Medium· 6.5gradio Server Side Request Forgery vulnerability
gradio Server Side Request Forgery vulnerability
GHSA-26jh-r8g2-6fprMedium· 5.3Gradio's dropdown component pre-process step does not limit the values to those in the dropdown list
Gradio's dropdown component pre-process step does not limit the values to those in the dropdown list
CVE-2024-4940Medium· 5.4PoCOpen redirect in gradio
Open redirect in gradio
CVE-2024-4325High· 8.6PoCServer-Side Request Forgery in gradio
Server-Side Request Forgery in gradio
CVE-2024-4253Critical· 9.1PoCA command injection vulnerability exists in the gradio-app/gradio repository, specifically within the 'test-functional.yml' workflow. The…
A command injection vulnerability exists in the gradio-app/gradio repository, specifically within the 'test-functional.yml' workflow. The vulnerability arises due to improper neutralization of special elements used in a command, allowing…
CVE-2024-1727Medium· 4.3Gradio applications running locally vulnerable to 3rd party websites accessing routes and uploading files
Gradio applications running locally vulnerable to 3rd party websites accessing routes and uploading files
CVE-2024-34511Medium· 6.5Gradio's Component Server does not properly consider` _is_server_fn` for functions
Gradio's Component Server does not properly consider` _is_server_fn` for functions
CVE-2024-1183Medium· 6.5PoCgradio Server-Side Request Forgery vulnerability
gradio Server-Side Request Forgery vulnerability
CVE-2024-1561High· 7.5PoCgradio vulnerable to Path Traversal
gradio vulnerable to Path Traversal
CVE-2024-2206High· 7.3gradio Server-Side Request Forgery vulnerability
gradio Server-Side Request Forgery vulnerability
CVE-2024-1729Medium· 5.9Gradio apps vulnerable to timing attacks to guess password
Gradio apps vulnerable to timing attacks to guess password
CVE-2023-51449High· 8.6PoCGradio makes the `/file` secure against file traversal and server-side request forgery attacks
Gradio makes the `/file` secure against file traversal and server-side request forgery attacks
CVE-2023-6572Critical· 9.6PoCGradio Exposure of Sensitive Information to an Unauthorized Actor vulnerability
Gradio Exposure of Sensitive Information to an Unauthorized Actor vulnerability
CVE-2023-41626Medium· 4.8Gradio arbitrary file upload vulnerability
Gradio arbitrary file upload vulnerability
CVE-2023-34239High· 7.3Gradio vulnerable to arbitrary file read and proxying of arbitrary URLs
Gradio vulnerable to arbitrary file read and proxying of arbitrary URLs
CVE-2023-25823Medium· 5.4Update share links to use FRP instead of SSH tunneling
Update share links to use FRP instead of SSH tunneling
CVE-2021-43831High· 8.3PoCFiles on the host computer can be accessed from the Gradio interface
Files on the host computer can be accessed from the Gradio interface