GradioGHSA-pgfv-gvc5-prfg
Gradio Vulnerable to Arbitrary File Deletion
High8.2CVE-2024-10648 · Published Mar 20, 2025 · updated Jul 7, 2026
A path traversal vulnerability exists in the Gradio Audio component of gradio-app/gradio, as of version git 98cbcae. This vulnerability allows an attacker to control the format of the audio file, leading to arbitrary file content deletion. By manipulating the output format, an attacker can reset any file to an empty file, causing a denial of service (DOS) on the server.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| gradio PyPI | >= 4.0.0, <= 5.0.0b2 | No fix yet |
Details and references
- CVSS 3.0
- CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H
- Severity from
- GitHub (reviewed advisory)
- Weakness
- CWE-29
- Also known as
- CVE-2024-10648, PYSEC-2026-1417
More Gradio advisories
All Gradio| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Mar 202025 | Gradio DOS in multipart boundry while uploading the file | High7.5 | No fix yet |
| Mar 202025 | Gradio Vulnerable to Open Redirect | Medium5.4 | No fix yet |
| Mar 202025 | Gradio Path Traversal vulnerability | Medium5.3 | No fix yet |
| Mar 202025 | Gradio Vulnerable to Denial of Service (DoS) via Crafted Zip Bomb | High7.5 | No fix yet |
| Mar 202025 | Gradio Vulnerable to Denial of Service (DoS) via Crafted HTTP Request | High7.5 | No fix yet |
| Jan 142025 | Gradio Blocked Path ACL Bypass Vulnerability | Critical | 5.11.0 |