vciy

CVEs we hold for Gradio-app

Records whose assigning authority named Gradio-app as the affected vendor. Newest identifiers first, capped at 200.

CVE-2026-59806Gradio < 6.20.0 - Open Redirect and SSRF via /gradio_api/file= endpointgradio-app gradio
CVE-2026-49119Gradio < 6.16.0 Path Traversal via FileExplorer.preprocess()gradio-app gradio
CVE-2026-48545Gradio < 6.15.0 Cookie Injection via Shared Proxy Clientgradio-app gradio
CVE-2026-28416Gradio has SSRF via Malicious `proxy_url` Injection in `gr.load()` Config Processinggradio-app gradio
CVE-2026-28415Gradio has Open Redirect in OAuth Flowgradio-app gradio
CVE-2026-28414Gradio has Absolute Path Traversal on Windows with Python 3.13+gradio-app gradio
CVE-2026-27167Gradio: Mocked OAuth Login Exposes Server Credentials and Uses Hardcoded Session Secretgradio-app gradio
CVE-2026-10783gradio-app gradio Audio Cache Key save_audio_to_cache weak hashgradio-app gradio
CVE-2025-5320gradio-app gradio CORS is_valid_origin privilege escalationgradio-app gradio
CVE-2025-48889Gradio Allows Unauthorized File Copy via Path Manipulationgradio-app gradio
CVE-2025-23042Gradio Blocked Path ACL Bypass Vulnerabilitygradio-app gradio
CVE-2025-0187Denial of Service (DoS) by Sending Large Filename at File Upload Endpoint in gradio-app/gradiogradio-app/gradio
CVE-2024-8966Denial of Service in gradio-app/gradiogradio-app/gradio
CVE-2024-8021Open Redirect in gradio-app/gradiogradio-app/gradio
CVE-2024-51751Arbitrary file read with File and UploadButton components in Gradiogradio-app gradio
CVE-2024-4941Local File Inclusion in JSON component in gradio-app/gradiogradio-app/gradio
CVE-2024-4940Open Redirect in gradio-app/gradiogradio-app/gradio
CVE-2024-47872Cross-site Scripting on Gradio server via upload of HTML files, JS files, or SVG filesgradio-app gradio
CVE-2024-47871Insecure communication between the FRP client and server in Gradiogradio-app gradio
CVE-2024-47870Race condition in update_root_in_config may redirect user traffic in Gradiogradio-app gradio
CVE-2024-47869Non-constant-time comparison when comparing hashes in Gradiogradio-app gradio
CVE-2024-47868Several components’ post-process steps may allow arbitrary file leaks in Gradiogradio-app gradio
CVE-2024-47867Lack of integrity check on the downloaded FRP client in Gradiogradio-app gradio
CVE-2024-47168The `enable_monitoring` flag set to `False` does not disable monitoring in Gradiogradio-app gradio
CVE-2024-47167SSRF in the path parameter of /queue/join in Gradiogradio-app gradio
CVE-2024-47166One-level read path traversal in `/custom_component` in Gradiogradio-app gradio
CVE-2024-47165CORS origin validation accepts the null origin in Gradiogradio-app gradio
CVE-2024-47164The `is_in_or_equal` function may be bypassed in Gradiogradio-app gradio
CVE-2024-47084CORS origin validation is not performed when the request has a cookie in Gradiogradio-app gradio
CVE-2024-4325Server-Side Request Forgery (SSRF) in gradio-app/gradiogradio-app/gradio
CVE-2024-4254Secrets Exfiltration in gradio-app/gradiogradio-app/gradio
CVE-2024-4253Command Injection in gradio-app/gradiogradio-app/gradio
CVE-2024-2206SSRF Vulnerability in gradio-app/gradiogradio-app/gradio
CVE-2024-1729Timing Attack Vulnerability in gradio-app/gradiogradio-app/gradio
CVE-2024-1728Local File Inclusion in gradio-app/gradiogradio-app/gradio
CVE-2024-1727CSRF Vulnerability in gradio-app/gradiogradio-app/gradio
CVE-2024-1561Arbitrary Local File Read via Component Method Invocation in gradio-app/gradiogradio-app/gradio
CVE-2024-1540Command Injection in gradio-app/gradio via deploy+test-visual.yml workflowgradio-app/gradio
CVE-2024-12217Path Traversal in gradio-app/gradiogradio-app/gradio
CVE-2024-1183SSRF Vulnerability in gradio-app/gradiogradio-app/gradio
CVE-2024-10648Path Traversal in gradio-app/gradiogradio-app/gradio
CVE-2024-10624Regular Expression Denial of Service (ReDoS) in gradio-app/gradiogradio-app/gradio
CVE-2024-10569Zip Bomb Vulnerability in gradio-app/gradiogradio-app/gradio
CVE-2024-0964LFI in Gradiogradio-app/gradio
CVE-2023-6572Command Injection in gradio-app/gradiogradio-app/gradio
CVE-2023-51449Make the `/file` secure against file traversal attacksgradio-app gradio
CVE-2023-34239Unfiltered paths in gradiogradio-app gradio
CVE-2023-25823Gradio contains Use of Hard-coded Credentialsgradio-app gradio
CVE-2022-24770Improper Neutralization of Formula Elements in a CSV File in Gradio Flagginggradio-app gradio
CVE-2021-43831Files on the host computer can be accessed from the Gradio interfacegradio-app gradio

50 records, read from the index as it stood on 20 Sep 2026. Every row opens the record it names, and every value on that record opens its own receipt.

Everything on this page is free. Public data. Withholding it protects nothing.