Skip to content
GradioGHSA-pgfv-gvc5-prfg

Gradio Vulnerable to Arbitrary File Deletion

High8.2CVE-2024-10648 · Published Mar 20, 2025 · updated Jul 7, 2026

A path traversal vulnerability exists in the Gradio Audio component of gradio-app/gradio, as of version git 98cbcae. This vulnerability allows an attacker to control the format of the audio file, leading to arbitrary file content deletion. By manipulating the output format, an attacker can reset any file to an empty file, causing a denial of service (DOS) on the server.

GitHub advisory

Affected versions

PackageAffectedFixed in
gradio
PyPI
>= 4.0.0, <= 5.0.0b2No fix yet
Details and references

More Gradio advisories

All Gradio
Advisory
Gradio DOS in multipart boundry while uploading the file
High7.5Mar 20, 2025
Gradio Vulnerable to Open Redirect
Medium5.4Mar 20, 2025
Gradio Path Traversal vulnerability
Medium5.3Mar 20, 2025
Gradio Vulnerable to Denial of Service (DoS) via Crafted Zip Bomb
High7.5Mar 20, 2025
Gradio Vulnerable to Denial of Service (DoS) via Crafted HTTP Request
High7.5Mar 20, 2025
Gradio Blocked Path ACL Bypass Vulnerability
CriticalJan 14, 2025

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.