Skip to content
GradioGHSA-6qm2-wpxq-7qh2

Gradio makes the `/file` secure against file traversal and server-side request forgery attacks

High8.6CVE-2023-51449 · Published Dec 21, 2023 · updated Sep 10, 2026

Older versions of `gradio` contained a vulnerability in the `/file` route which made them susceptible to file traversal attacks in which an attacker could access arbitrary files on a machine running a Gradio app with a public URL (e.g. if the demo was created with `share=True`, or on Hugging Face Spaces) if they knew the path of files to look for. This was not possible through regular URLs passed into a browser, but it was possible through the use of programmatic tools such as `curl` with the `--pass-as-is` flag. Furthermore, the `/file` route in Gradio apps also contained a vulnerability that made it possible to use it for SSRF attacks. Both of these vulnerabilities have been fixed in `gradio==4.11.0`

GitHub advisory

Affected versions

PackageAffectedFixed in
gradio
PyPI
< 4.11.04.11.0
Details and references

More Gradio advisories

All Gradio
Advisory
gradio Server-Side Request Forgery vulnerability
Medium6.5Apr 16, 2024
gradio Server-Side Request Forgery vulnerability
High7.3Mar 27, 2024
Gradio apps vulnerable to timing attacks to guess password
Medium5.9Feb 22, 2024
Gradio Path Traversal vulnerability
High7.5Feb 6, 2024
Gradio Exposure of Sensitive Information to an Unauthorized Actor vulnerability
Critical9.6Dec 14, 2023
Gradio arbitrary file upload vulnerability
Medium4.8Sep 16, 2023

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.