Gradio Project

Gradio

47 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.02%
  • Veröffentlicht 27.02.2026 21:47:04
  • Zuletzt bearbeitet 05.03.2026 13:03:21

Gradio is an open-source Python package designed for quick prototyping. Prior to version 6.6.0, a Server-Side Request Forgery (SSRF) vulnerability in Gradio allows an attacker to make arbitrary HTTP requests from a victim's server by hosting a malici...

  • EPSS 0.01%
  • Veröffentlicht 27.02.2026 21:44:51
  • Zuletzt bearbeitet 05.03.2026 13:06:31

Gradio is an open-source Python package designed for quick prototyping. Prior to version 6.6.0, the _redirect_to_target() function in Gradio's OAuth flow accepts an unvalidated _target_url query parameter, allowing redirection to arbitrary external U...

Exploit
  • EPSS 2.28%
  • Veröffentlicht 27.02.2026 21:43:28
  • Zuletzt bearbeitet 05.03.2026 13:09:59

Gradio is an open-source Python package designed for quick prototyping. Prior to version 6.7, Gradio apps running on Window with Python 3.13+ are vulnerable to an absolute path traversal issue that enables unauthenticated attackers to read arbitrary ...

Exploit
  • EPSS 0.03%
  • Veröffentlicht 27.02.2026 21:40:57
  • Zuletzt bearbeitet 05.03.2026 13:13:11

Gradio is an open-source Python package designed for quick prototyping. Starting in version 4.16.0 and prior to version 6.6.0, Gradio applications running outside of Hugging Face Spaces automatically enable "mocked" OAuth routes when OAuth components...

Exploit
  • EPSS 1.47%
  • Veröffentlicht 30.05.2025 06:12:32
  • Zuletzt bearbeitet 26.08.2025 16:28:02

Gradio is an open-source Python package that allows quick building of demos and web application for machine learning models, API, or any arbitrary Python function. Prior to version 5.31.0, an arbitrary file copy vulnerability in Gradio's flagging fea...

Exploit
  • EPSS 2.68%
  • Veröffentlicht 20.03.2025 10:11:13
  • Zuletzt bearbeitet 26.03.2025 16:39:28

An open redirect vulnerability exists in the latest version of gradio-app/gradio. The vulnerability allows an attacker to redirect users to a malicious website by URL encoding. This can be exploited by sending a crafted request to the application, wh...

Exploit
  • EPSS 0.25%
  • Veröffentlicht 20.03.2025 10:11:11
  • Zuletzt bearbeitet 14.10.2025 18:52:29

A path traversal vulnerability exists in the Gradio Audio component of gradio-app/gradio, as of version git 98cbcae. This vulnerability allows an attacker to control the format of the audio file, leading to arbitrary file content deletion. By manipul...

Exploit
  • EPSS 0.16%
  • Veröffentlicht 20.03.2025 10:10:57
  • Zuletzt bearbeitet 07.10.2025 20:58:52

A vulnerability in the dataframe component of gradio-app/gradio (version git 98cbcae) allows for a zip bomb attack. The component uses pd.read_csv to process input values, which can accept compressed files. An attacker can exploit this by uploading a...

Exploit
  • EPSS 0.78%
  • Veröffentlicht 20.03.2025 10:10:43
  • Zuletzt bearbeitet 15.10.2025 13:15:36

A Regular Expression Denial of Service (ReDoS) vulnerability exists in the gradio-app/gradio repository, affecting the gr.Datetime component. The affected version is git commit 98cbcae. The vulnerability arises from the use of a regular expression `^...

Exploit
  • EPSS 0.62%
  • Veröffentlicht 20.03.2025 10:10:42
  • Zuletzt bearbeitet 01.08.2025 18:09:31

A Denial of Service (DoS) vulnerability was discovered in the file upload feature of gradio-app/gradio version 0.39.1. The vulnerability is due to improper handling of form-data with a large filename in the file upload request. By sending a payload w...