Skip to content
GradioGHSA-qh6x-j82h-vpf9

gradio Server-Side Request Forgery vulnerability

Medium6.5CVE-2024-1183 · Published Apr 16, 2024 · updated Sep 10, 2026

An SSRF (Server-Side Request Forgery) vulnerability exists in the gradio-app/gradio repository, allowing attackers to scan and identify open ports within an internal network. By manipulating the 'file' parameter in a GET request, an attacker can discern the status of internal ports based on the presence of a 'Location' header or a 'File not allowed' error in the response.

GitHub advisory

Affected versions

PackageAffectedFixed in
gradio
PyPI
< 4.10.04.10.0
Details and references

More Gradio advisories

All Gradio
Advisory
Gradio: command injection
Critical9.1Jun 4, 2024
Gradio applications running locally vulnerable to 3rd party websites accessing routes and uploading files
Medium4.3May 21, 2024
Gradio allows credential leakage on Windows
High7.5May 5, 2024
Gradio's Component Server does not properly consider` _is_server_fn` for functions
Medium6.5May 5, 2024
gradio vulnerable to Path Traversal
High7.5Apr 16, 2024
gradio Server-Side Request Forgery vulnerability
High7.3Mar 27, 2024

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.