GradioGHSA-7v2w-h4gh-w5cv
Gradio Vulnerable to Open Redirect
Medium5.4CVE-2024-8021 · Published Mar 20, 2025 · updated Jul 7, 2026
An open redirect vulnerability exists in the latest version of gradio-app/gradio. The vulnerability allows an attacker to redirect users to a malicious website by URL encoding. This can be exploited by sending a crafted request to the application, which results in a 302 redirect to an attacker-controlled site.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| gradio PyPI | <= 4.37.2 | No fix yet |
Details and references
- CVSS 3.0
- CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N
- Severity from
- GitHub (reviewed advisory)
- Weakness
- CWE-601
- Also known as
- CVE-2024-8021, PYSEC-2026-1411
More Gradio advisories
All Gradio| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Mar 202025 | Gradio DOS in multipart boundry while uploading the file | High7.5 | No fix yet |
| Mar 202025 | Gradio Path Traversal vulnerability | Medium5.3 | No fix yet |
| Mar 202025 | Gradio Vulnerable to Denial of Service (DoS) via Crafted Zip Bomb | High7.5 | No fix yet |
| Mar 202025 | Gradio Vulnerable to Arbitrary File Deletion | High8.2 | No fix yet |
| Mar 202025 | Gradio Vulnerable to Denial of Service (DoS) via Crafted HTTP Request | High7.5 | No fix yet |
| Jan 142025 | Gradio Blocked Path ACL Bypass Vulnerability | Critical | 5.11.0 |