CVEs we hold for Gradio-app
Records whose assigning authority named Gradio-app as the affected vendor. Newest identifiers first, capped at 200.
CVE-2026-59806Gradio < 6.20.0 - Open Redirect and SSRF via /gradio_api/file= endpointgradio-app gradio CVE-2026-49119Gradio < 6.16.0 Path Traversal via FileExplorer.preprocess()gradio-app gradio CVE-2026-48545Gradio < 6.15.0 Cookie Injection via Shared Proxy Clientgradio-app gradio CVE-2026-28416Gradio has SSRF via Malicious `proxy_url` Injection in `gr.load()` Config Processinggradio-app gradio CVE-2026-28414Gradio has Absolute Path Traversal on Windows with Python 3.13+gradio-app gradio CVE-2026-27167Gradio: Mocked OAuth Login Exposes Server Credentials and Uses Hardcoded Session Secretgradio-app gradio CVE-2026-10783gradio-app gradio Audio Cache Key save_audio_to_cache weak hashgradio-app gradio CVE-2025-5320gradio-app gradio CORS is_valid_origin privilege escalationgradio-app gradio CVE-2025-48889Gradio Allows Unauthorized File Copy via Path Manipulationgradio-app gradio CVE-2025-23042Gradio Blocked Path ACL Bypass Vulnerabilitygradio-app gradio CVE-2025-0187Denial of Service (DoS) by Sending Large Filename at File Upload Endpoint in gradio-app/gradiogradio-app/gradio CVE-2024-8966Denial of Service in gradio-app/gradiogradio-app/gradio CVE-2024-51751Arbitrary file read with File and UploadButton components in Gradiogradio-app gradio CVE-2024-4941Local File Inclusion in JSON component in gradio-app/gradiogradio-app/gradio CVE-2024-47872Cross-site Scripting on Gradio server via upload of HTML files, JS files, or SVG filesgradio-app gradio CVE-2024-47871Insecure communication between the FRP client and server in Gradiogradio-app gradio CVE-2024-47870Race condition in update_root_in_config may redirect user traffic in Gradiogradio-app gradio CVE-2024-47869Non-constant-time comparison when comparing hashes in Gradiogradio-app gradio CVE-2024-47868Several components’ post-process steps may allow arbitrary file leaks in Gradiogradio-app gradio CVE-2024-47867Lack of integrity check on the downloaded FRP client in Gradiogradio-app gradio CVE-2024-47168The `enable_monitoring` flag set to `False` does not disable monitoring in Gradiogradio-app gradio CVE-2024-47167SSRF in the path parameter of /queue/join in Gradiogradio-app gradio CVE-2024-47166One-level read path traversal in `/custom_component` in Gradiogradio-app gradio CVE-2024-47165CORS origin validation accepts the null origin in Gradiogradio-app gradio CVE-2024-47164The `is_in_or_equal` function may be bypassed in Gradiogradio-app gradio CVE-2024-47084CORS origin validation is not performed when the request has a cookie in Gradiogradio-app gradio CVE-2024-4325Server-Side Request Forgery (SSRF) in gradio-app/gradiogradio-app/gradio CVE-2024-4254Secrets Exfiltration in gradio-app/gradiogradio-app/gradio CVE-2024-4253Command Injection in gradio-app/gradiogradio-app/gradio CVE-2024-2206SSRF Vulnerability in gradio-app/gradiogradio-app/gradio CVE-2024-1729Timing Attack Vulnerability in gradio-app/gradiogradio-app/gradio CVE-2024-1728Local File Inclusion in gradio-app/gradiogradio-app/gradio CVE-2024-1727CSRF Vulnerability in gradio-app/gradiogradio-app/gradio CVE-2024-1561Arbitrary Local File Read via Component Method Invocation in gradio-app/gradiogradio-app/gradio CVE-2024-1540Command Injection in gradio-app/gradio via deploy+test-visual.yml workflowgradio-app/gradio CVE-2024-1183SSRF Vulnerability in gradio-app/gradiogradio-app/gradio CVE-2024-10624Regular Expression Denial of Service (ReDoS) in gradio-app/gradiogradio-app/gradio CVE-2024-10569Zip Bomb Vulnerability in gradio-app/gradiogradio-app/gradio CVE-2023-6572Command Injection in gradio-app/gradiogradio-app/gradio CVE-2023-51449Make the `/file` secure against file traversal attacksgradio-app gradio CVE-2023-25823Gradio contains Use of Hard-coded Credentialsgradio-app gradio CVE-2022-24770Improper Neutralization of Formula Elements in a CSV File in Gradio Flagginggradio-app gradio CVE-2021-43831Files on the host computer can be accessed from the Gradio interfacegradio-app gradio 50 records, read from the index as it stood on 20 Sep 2026. Every row opens the record it names, and every value on that record opens its own receipt.
Everything on this page is free. Public data. Withholding it protects nothing.