Skip to content
GradioGHSA-f3h9-8phc-6gvh

Gradio Path Traversal vulnerability

High7.5CVE-2024-0964 · Published Feb 6, 2024 · updated May 19, 2026

A local file include could be remotely triggered in Gradio due to a vulnerable user-supplied JSON value in an API request.

GitHub advisory

Affected versions

PackageAffectedFixed in
gradio
PyPI
< 4.9.04.9.0
Details and references

More Gradio advisories

All Gradio
Advisory
gradio vulnerable to Path Traversal
High7.5Apr 16, 2024
gradio Server-Side Request Forgery vulnerability
Medium6.5Apr 16, 2024
gradio Server-Side Request Forgery vulnerability
High7.3Mar 27, 2024
Gradio apps vulnerable to timing attacks to guess password
Medium5.9Feb 22, 2024
Gradio makes the `/file` secure against file traversal and server-side request forgery attacks
High8.6Dec 21, 2023
Gradio Exposure of Sensitive Information to an Unauthorized Actor vulnerability
Critical9.6Dec 14, 2023

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.