GradioGHSA-34rf-p3r3-58x2
Gradio's Component Server does not properly consider` _is_server_fn` for functions
Medium6.5CVE-2024-34511 · Published May 5, 2024 · updated Sep 10, 2026
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| gradio PyPI | < 4.13.0 | 4.13.0 |
Details and references
Component Server in Gradio before 4.13 does not properly consider` _is_server_fn` for functions.
- CVSS 3.1
- CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:L/A:N
- Severity from
- GitHub (reviewed advisory)
- Also known as
- CVE-2024-34511, PYSEC-2026-1407
More Gradio advisories
All Gradio| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| May 52024 | Gradio allows credential leakage on Windows CVE-2024-34510High7.5fixed in 4.20.0 | High7.5 | 4.20.0 |
| May 212024 | Gradio applications running locally vulnerable to 3rd party websites accessing routes and uploading files CVE-2024-1727Medium4.3fixed in 4.19.2 | Medium4.3 | 4.19.2 |
| Apr 162024 | gradio vulnerable to Path Traversal CVE-2024-1561High7.5fixed in 4.13.0 | High7.5 | 4.13.0 |
| Apr 162024 | gradio Server-Side Request Forgery vulnerability CVE-2024-1183Medium6.5fixed in 4.10.0 | Medium6.5 | 4.10.0 |
| Jun 42024 | A command injection vulnerability exists in the gradio-app/gradio repository, specifically within the 'test-functional.yml' workflow. The vulnerability arises due to improper neutralization of special elements used in a command, allowing for unauthorized modification of the base repository or secret CVE-2024-4253Critical9.1fixed in 4.29.0 | Critical9.1 | 4.29.0 |
| Jun 62024 | Local file inclusion in gradio CVE-2024-4941High7.5fixed in 4.31.3 | High7.5 | 4.31.3 |