Gradio Project

Gradio

47 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 0.1%
  • Veröffentlicht 14.01.2025 19:15:44
  • Zuletzt bearbeitet 26.08.2025 16:46:48

Gradio is an open-source Python package that allows quick building of demos and web application for machine learning models, API, or any arbitrary Python function. Gradio's Access Control List (ACL) for file paths can be bypassed by altering the lett...

Exploit
  • EPSS 0.28%
  • Veröffentlicht 06.11.2024 20:15:05
  • Zuletzt bearbeitet 26.08.2025 16:34:42

Gradio is an open-source Python package designed to enable quick builds of a demo or web application. If File or UploadButton components are used as a part of Gradio application to preview file content, an attacker with access to the application migh...

Exploit
  • EPSS 0.13%
  • Veröffentlicht 04.11.2024 23:15:04
  • Zuletzt bearbeitet 13.06.2025 00:21:58

In gradio <=4.42.0, the gr.DownloadButton function has a hidden server-side request forgery (SSRF) vulnerability. The reason is that within the save_url_to_cache function, there are no restrictions on the URL, which allows access to local target reso...

  • EPSS 0.25%
  • Veröffentlicht 10.10.2024 23:15:03
  • Zuletzt bearbeitet 17.10.2024 16:54:34

Gradio is an open-source Python package designed for quick prototyping. This vulnerability involves **Cross-Site Scripting (XSS)** on any Gradio server that allows file uploads. Authenticated users can upload files such as HTML, JavaScript, or SVG fi...

  • EPSS 0.08%
  • Veröffentlicht 10.10.2024 23:15:03
  • Zuletzt bearbeitet 17.10.2024 17:11:31

Gradio is an open-source Python package designed for quick prototyping. This vulnerability involves **insecure communication** between the FRP (Fast Reverse Proxy) client and server when Gradio's `share=True` option is used. HTTPS is not enforced on ...

  • EPSS 0.19%
  • Veröffentlicht 10.10.2024 23:15:03
  • Zuletzt bearbeitet 17.10.2024 16:57:02

Gradio is an open-source Python package designed for quick prototyping. This vulnerability involves a **race condition** in the `update_root_in_config` function, allowing an attacker to modify the `root` URL used by the Gradio frontend to communicate...

  • EPSS 0.16%
  • Veröffentlicht 10.10.2024 23:15:02
  • Zuletzt bearbeitet 17.10.2024 16:59:04

Gradio is an open-source Python package designed for quick prototyping. This vulnerability involves a **timing attack** in the way Gradio compares hashes for the `analytics_dashboard` function. Since the comparison is not done in constant time, an at...

Exploit
  • EPSS 0.2%
  • Veröffentlicht 10.10.2024 23:15:02
  • Zuletzt bearbeitet 17.10.2024 17:04:35

Gradio is an open-source Python package designed for quick prototyping. This is a **data validation vulnerability** affecting several Gradio components, which allows arbitrary file leaks through the post-processing step. Attackers can exploit these c...

  • EPSS 0.22%
  • Veröffentlicht 10.10.2024 23:15:02
  • Zuletzt bearbeitet 15.11.2024 16:44:54

Gradio is an open-source Python package designed for quick prototyping. This vulnerability is a **lack of integrity check** on the downloaded FRP client, which could potentially allow attackers to introduce malicious code. If an attacker gains access...

  • EPSS 0.16%
  • Veröffentlicht 10.10.2024 22:15:11
  • Zuletzt bearbeitet 17.10.2024 17:00:47

Gradio is an open-source Python package designed for quick prototyping. This vulnerability involves data exposure due to the enable_monitoring flag not properly disabling monitoring when set to False. Even when monitoring is supposedly disabled, an a...