GradioGHSA-f3h9-8phc-6gvh
Gradio Path Traversal vulnerability
High7.5CVE-2024-0964 · Published Feb 6, 2024 · updated May 19, 2026
A local file include could be remotely triggered in Gradio due to a vulnerable user-supplied JSON value in an API request.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| gradio PyPI | < 4.9.0 | 4.9.0 |
Details and references
- CVSS 3.0
- CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
- Severity from
- GitHub (reviewed advisory)
- Weakness
- CWE-22
- Also known as
- CVE-2024-0964, PYSEC-2024-261
More Gradio advisories
All Gradio| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Apr 162024 | gradio vulnerable to Path Traversal | High7.5 | 4.13.0 |
| Apr 162024 | gradio Server-Side Request Forgery vulnerability | Medium6.5 | 4.10.0 |
| Mar 272024 | gradio Server-Side Request Forgery vulnerability | High7.3 | 4.18.0 |
| Feb 222024 | Gradio apps vulnerable to timing attacks to guess password | Medium5.9 | 4.19.2 |
| Dec 212023 | Gradio makes the `/file` secure against file traversal and server-side request forgery attacks | High8.6 | 4.11.0 |
| Dec 142023 | Gradio Exposure of Sensitive Information to an Unauthorized Actor vulnerability | Critical9.6 | 4.14.0 |