Skip to content
GradioGHSA-3gf9-wv65-gwh9

gradio Server Side Request Forgery vulnerability

Medium6.5CVE-2024-48052 · Published Nov 5, 2024 · updated Sep 10, 2026

In gradio <=4.42.0, the gr.DownloadButton function has a hidden server-side request forgery (SSRF) vulnerability. The reason is that within the save_url_to_cache function, there are no restrictions on the URL, which allows access to local target resources. This can lead to the download of local resources and sensitive information.

GitHub advisory

Affected versions

PackageAffectedFixed in
gradio
PyPI
<= 4.42.0No fix yet
Details and references

More Gradio advisories

All Gradio

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.