Gradio Project

Gradio

49 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 0.35%
  • Veröffentlicht 21.03.2024 20:15:07
  • Zuletzt bearbeitet 30.07.2025 20:11:16

A Cross-Site Request Forgery (CSRF) vulnerability in gradio-app/gradio allows attackers to upload multiple large files to a victim's system if they are running Gradio locally. By crafting a malicious HTML page that triggers an unauthorized file uploa...

Exploit
  • EPSS 0.95%
  • Veröffentlicht 05.02.2024 23:15:08
  • Zuletzt bearbeitet 21.11.2024 08:47:54

A local file include could be remotely triggered in Gradio due to a vulnerable user-supplied JSON value in an API request.

  • EPSS 2.28%
  • Veröffentlicht 22.12.2023 21:15:09
  • Zuletzt bearbeitet 21.11.2024 08:38:08

Gradio is an open-source Python package that allows you to quickly build a demo or web application for your machine learning model, API, or any arbitary Python function. Versions of `gradio` prior to 4.11.0 contained a vulnerability in the `/file` ro...

Exploit
  • EPSS 1.71%
  • Veröffentlicht 14.12.2023 14:15:46
  • Zuletzt bearbeitet 21.11.2024 08:44:07

Command Injection in GitHub repository gradio-app/gradio prior to main.

  • EPSS 0.35%
  • Veröffentlicht 15.09.2023 23:15:07
  • Zuletzt bearbeitet 21.11.2024 08:21:22

Gradio v3.27.0 was discovered to contain an arbitrary file upload vulnerability via the /upload interface.

  • EPSS 0.65%
  • Veröffentlicht 08.06.2023 00:15:09
  • Zuletzt bearbeitet 21.11.2024 08:06:50

Gradio is an open-source Python library that is used to build machine learning and data science. Due to a lack of path filtering Gradio does not properly restrict file access to users. Additionally Gradio does not properly restrict the what URLs are ...

  • EPSS 0.55%
  • Veröffentlicht 23.02.2023 22:15:11
  • Zuletzt bearbeitet 21.11.2024 07:50:16

Gradio is an open-source Python library to build machine learning and data science demos and web applications. Versions prior to 3.13.1 contain Use of Hard-coded Credentials. When using Gradio's share links (i.e. creating a Gradio app and then settin...

  • EPSS 1.25%
  • Veröffentlicht 17.03.2022 21:15:08
  • Zuletzt bearbeitet 21.11.2024 06:51:03

`gradio` is an open source framework for building interactive machine learning models and demos. Prior to version 2.8.11, `gradio` suffers from Improper Neutralization of Formula Elements in a CSV File. The `gradio` library has a flagging functionali...

Exploit
  • EPSS 3.79%
  • Veröffentlicht 15.12.2021 20:15:08
  • Zuletzt bearbeitet 21.11.2024 06:29:53

Gradio is an open source framework for building interactive machine learning models and demos. In versions prior to 2.5.0 there is a vulnerability that affects anyone who creates and publicly shares Gradio interfaces. File paths are not restricted an...