GradioGHSA-qh6x-j82h-vpf9
gradio Server-Side Request Forgery vulnerability
Medium6.5CVE-2024-1183 · Published Apr 16, 2024 · updated Sep 10, 2026
An SSRF (Server-Side Request Forgery) vulnerability exists in the gradio-app/gradio repository, allowing attackers to scan and identify open ports within an internal network. By manipulating the 'file' parameter in a GET request, an attacker can discern the status of internal ports based on the presence of a 'Location' header or a 'File not allowed' error in the response.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| gradio PyPI | < 4.10.0 | 4.10.0 |
Details and references
- CVSS 3.0
- CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
- Severity from
- GitHub (reviewed advisory)
- Weakness
- CWE-601
- Also known as
- CVE-2024-1183, PYSEC-2026-1419
More Gradio advisories
All Gradio| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Jun 42024 | Gradio: command injection | Critical9.1 | 4.29.0 |
| May 212024 | Gradio applications running locally vulnerable to 3rd party websites accessing routes and uploading files | Medium4.3 | 4.19.2 |
| May 52024 | Gradio allows credential leakage on Windows | High7.5 | 4.20.0 |
| May 52024 | Gradio's Component Server does not properly consider` _is_server_fn` for functions | Medium6.5 | 4.13.0 |
| Apr 162024 | gradio vulnerable to Path Traversal | High7.5 | 4.13.0 |
| Mar 272024 | gradio Server-Side Request Forgery vulnerability | High7.3 | 4.18.0 |