Skip to content
GradioGHSA-gqvf-3hgp-5hxv

Gradio Exposure of Sensitive Information to an Unauthorized Actor vulnerability

Critical9.6CVE-2023-6572 · Published Dec 14, 2023 · updated Sep 10, 2026

GitHub advisory

Affected versions

PackageAffectedFixed in
gradio
PyPI
< 4.14.04.14.0
Details and references

Exposure of Sensitive Information to an Unauthorized Actor in GitHub repository gradio-app/gradio prior to main.

CVSS 3.0
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N
Severity from
GitHub (reviewed advisory)
Weakness
CWE-200, CWE-77
Also known as
CVE-2023-6572, PYSEC-2023-255

More Gradio advisories

All Gradio
DateAdvisory
Dec 212023Gradio makes the `/file` secure against file traversal and server-side request forgery attacks
CVE-2023-51449High8.6fixed in 4.11.0
Feb 62024Gradio Path Traversal vulnerability
CVE-2024-0964High7.5fixed in 4.9.0
Feb 222024Gradio apps vulnerable to timing attacks to guess password
CVE-2024-1729Medium5.9fixed in 4.19.2
Sep 162023Gradio arbitrary file upload vulnerability
CVE-2023-41626Medium4.8no fix yet
Mar 272024gradio Server-Side Request Forgery vulnerability
CVE-2024-2206High7.3fixed in 4.18.0
Apr 162024gradio Server-Side Request Forgery vulnerability
CVE-2024-1183Medium6.5fixed in 4.10.0

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.