Gradio Project

Gradio

49 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 1.02%
  • Veröffentlicht 20.03.2025 10:10:43
  • Zuletzt bearbeitet 15.10.2025 13:15:36

A Regular Expression Denial of Service (ReDoS) vulnerability exists in the gradio-app/gradio repository, affecting the gr.Datetime component. The affected version is git commit 98cbcae. The vulnerability arises from the use of a regular expression `^...

Exploit
  • EPSS 0.68%
  • Veröffentlicht 20.03.2025 10:10:42
  • Zuletzt bearbeitet 01.08.2025 18:09:31

A Denial of Service (DoS) vulnerability was discovered in the file upload feature of gradio-app/gradio version 0.39.1. The vulnerability is due to improper handling of form-data with a large filename in the file upload request. By sending a payload w...

Exploit
  • EPSS 0.84%
  • Veröffentlicht 14.01.2025 19:15:44
  • Zuletzt bearbeitet 26.08.2025 16:46:48

Gradio is an open-source Python package that allows quick building of demos and web application for machine learning models, API, or any arbitrary Python function. Gradio's Access Control List (ACL) for file paths can be bypassed by altering the lett...

Exploit
  • EPSS 0.67%
  • Veröffentlicht 06.11.2024 20:15:05
  • Zuletzt bearbeitet 26.08.2025 16:34:42

Gradio is an open-source Python package designed to enable quick builds of a demo or web application. If File or UploadButton components are used as a part of Gradio application to preview file content, an attacker with access to the application migh...

Exploit
  • EPSS 0.46%
  • Veröffentlicht 04.11.2024 23:15:04
  • Zuletzt bearbeitet 13.06.2025 00:21:58

In gradio <=4.42.0, the gr.DownloadButton function has a hidden server-side request forgery (SSRF) vulnerability. The reason is that within the save_url_to_cache function, there are no restrictions on the URL, which allows access to local target reso...

  • EPSS 0.25%
  • Veröffentlicht 10.10.2024 23:15:03
  • Zuletzt bearbeitet 17.10.2024 16:54:34

Gradio is an open-source Python package designed for quick prototyping. This vulnerability involves **Cross-Site Scripting (XSS)** on any Gradio server that allows file uploads. Authenticated users can upload files such as HTML, JavaScript, or SVG fi...

  • EPSS 0.17%
  • Veröffentlicht 10.10.2024 23:15:03
  • Zuletzt bearbeitet 17.10.2024 17:11:31

Gradio is an open-source Python package designed for quick prototyping. This vulnerability involves **insecure communication** between the FRP (Fast Reverse Proxy) client and server when Gradio's `share=True` option is used. HTTPS is not enforced on ...

  • EPSS 0.36%
  • Veröffentlicht 10.10.2024 23:15:03
  • Zuletzt bearbeitet 17.10.2024 16:57:02

Gradio is an open-source Python package designed for quick prototyping. This vulnerability involves a **race condition** in the `update_root_in_config` function, allowing an attacker to modify the `root` URL used by the Gradio frontend to communicate...

  • EPSS 0.29%
  • Veröffentlicht 10.10.2024 23:15:02
  • Zuletzt bearbeitet 17.10.2024 16:59:04

Gradio is an open-source Python package designed for quick prototyping. This vulnerability involves a **timing attack** in the way Gradio compares hashes for the `analytics_dashboard` function. Since the comparison is not done in constant time, an at...

Exploit
  • EPSS 0.8%
  • Veröffentlicht 10.10.2024 23:15:02
  • Zuletzt bearbeitet 17.10.2024 17:04:35

Gradio is an open-source Python package designed for quick prototyping. This is a **data validation vulnerability** affecting several Gradio components, which allows arbitrary file leaks through the post-processing step. Attackers can exploit these c...