Skip to content
GradioGHSA-973g-55hp-3frw

Server-Side Request Forgery in gradio

High8.6CVE-2024-4325 · Published Jun 6, 2024 · updated Sep 10, 2026

GitHub advisory

Affected versions

PackageAffectedFixed in
gradio
PyPI
<= 4.36.0No fix yet
Details and references

A Server-Side Request Forgery (SSRF) vulnerability exists in the gradio-app/gradio and was discovered in version 4.21.0, specifically within the `/queue/join` endpoint and the `save_url_to_cache` function. The vulnerability arises when the `path` value, obtained from the user and expected to be a URL, is used to make an HTTP request without sufficient validation checks. This flaw allows an attacker to send crafted requests that could lead to unauthorized access to the local network or the AWS metadata endpoint, thereby compromising the security of internal servers.

CVSS 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N
Severity from
GitHub (reviewed advisory)
Weakness
CWE-918
Also known as
CVE-2024-4325, PYSEC-2026-1413

More Gradio advisories

All Gradio

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.