Skip to content
GradioGHSA-rvfh-h6c7-fc3c

Gradio allows credential leakage on Windows

High7.5CVE-2024-34510 · Published May 5, 2024 · updated Jun 17, 2025

Gradio before 4.20 allows credential leakage on Windows.

GitHub advisory

Affected versions

PackageAffectedFixed in
gradio
PyPI
< 4.20.04.20.0
Details and references
CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Severity from
GitHub (reviewed advisory)
Weakness
CWE-116
Also known as
CVE-2024-34510, PYSEC-2024-255

More Gradio advisories

All Gradio
Advisory
Server-Side Request Forgery in gradio
High8.6Jun 6, 2024
Gradio: command injection
Critical9.1Jun 4, 2024
Gradio applications running locally vulnerable to 3rd party websites accessing routes and uploading files
Medium4.3May 21, 2024
Gradio's Component Server does not properly consider` _is_server_fn` for functions
Medium6.5May 5, 2024
gradio vulnerable to Path Traversal
High7.5Apr 16, 2024
gradio Server-Side Request Forgery vulnerability
Medium6.5Apr 16, 2024

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.