GradioGHSA-gqvf-3hgp-5hxv
Gradio Exposure of Sensitive Information to an Unauthorized Actor vulnerability
Critical9.6CVE-2023-6572 · Published Dec 14, 2023 · updated Sep 10, 2026
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| gradio PyPI | < 4.14.0 | 4.14.0 |
Details and references
More Gradio advisories
All Gradio| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Dec 212023 | Gradio makes the `/file` secure against file traversal and server-side request forgery attacks CVE-2023-51449High8.6fixed in 4.11.0 | High8.6 | 4.11.0 |
| Feb 62024 | Gradio Path Traversal vulnerability CVE-2024-0964High7.5fixed in 4.9.0 | High7.5 | 4.9.0 |
| Feb 222024 | Gradio apps vulnerable to timing attacks to guess password CVE-2024-1729Medium5.9fixed in 4.19.2 | Medium5.9 | 4.19.2 |
| Sep 162023 | Gradio arbitrary file upload vulnerability CVE-2023-41626Medium4.8no fix yet | Medium4.8 | No fix yet |
| Mar 272024 | gradio Server-Side Request Forgery vulnerability CVE-2024-2206High7.3fixed in 4.18.0 | High7.3 | 4.18.0 |
| Apr 162024 | gradio Server-Side Request Forgery vulnerability CVE-2024-1183Medium6.5fixed in 4.10.0 | Medium6.5 | 4.10.0 |