Skip to content
GradioGHSA-f8xq-q7px-wg8c

Improper Neutralization of Formula Elements in a CSV File in Gradio Flagging

High8.8CVE-2022-24770 · Published Mar 18, 2022 · updated Nov 8, 2023

### Impact The `gradio` library has a flagging functionality which saves input/output data into a CSV file on the developer's computer. This can allow a user to save arbitrary text into the CSV file, such as commands. If a program like MS Excel opens such a file, then it automatically runs these commands, which could lead to arbitrary commands running on the user's computer. ### Patches The problem has been patched as of `2.8.11`, which escapes the data saved to the csv with single quotes. ### Workarounds If you are using an older version of `gradio`, don't open csv files generated by `gradio` with Excel or similar spreadsheet programs.

GitHub advisory

Affected versions

PackageAffectedFixed in
gradio
PyPI
< 2.8.112.8.11
Details and references

More Gradio advisories

All Gradio
Advisory
Gradio makes the `/file` secure against file traversal and server-side request forgery attacks
High8.6Dec 21, 2023
Gradio Exposure of Sensitive Information to an Unauthorized Actor vulnerability
Critical9.6Dec 14, 2023
Gradio arbitrary file upload vulnerability
Medium4.8Sep 16, 2023
Gradio vulnerable to arbitrary file read and proxying of arbitrary URLs
Medium7.3Jun 9, 2023
Update share links to use FRP instead of SSH tunneling
Medium5.4Feb 23, 2023
Files on the host computer can be accessed from the Gradio interface
Critical8.3Jan 21, 2022

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.