Skip to content
GradioGHSA-g6c9-f4xm-9j4x

Open redirect in gradio

Medium5.4CVE-2024-4940 · Published Jun 22, 2024 · updated Sep 10, 2026

An open redirect vulnerability exists in the gradio-app/gradio, affecting the latest version. The vulnerability allows an attacker to redirect users to arbitrary websites, which can be exploited for phishing attacks, Cross-site Scripting (XSS), Server-Side Request Forgery (SSRF), amongst others. This issue is due to improper validation of user-supplied input in the handling of URLs. Attackers can exploit this vulnerability by crafting a malicious URL that, when processed by the application, redirects the user to an attacker-controlled web page.

GitHub advisory

Affected versions

PackageAffectedFixed in
gradio
PyPI
<= 4.36.1No fix yet
Details and references
CVSS 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N
Severity from
GitHub (reviewed advisory)
Weakness
CWE-601
Also known as
CVE-2024-4940, PYSEC-2026-1414

More Gradio advisories

All Gradio
Advisory
Gradio: code injection
Critical9.8Jul 1, 2024
Local file inclusion in gradio
High7.5Jun 6, 2024
Server-Side Request Forgery in gradio
High8.6Jun 6, 2024
Gradio: command injection
Critical9.1Jun 4, 2024
Gradio applications running locally vulnerable to 3rd party websites accessing routes and uploading files
Medium4.3May 21, 2024
Gradio's Component Server does not properly consider` _is_server_fn` for functions
Medium6.5May 5, 2024

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.