GradioGHSA-rvfh-h6c7-fc3c
Gradio allows credential leakage on Windows
High7.5CVE-2024-34510 · Published May 5, 2024 · updated Jun 17, 2025
Gradio before 4.20 allows credential leakage on Windows.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| gradio PyPI | < 4.20.0 | 4.20.0 |
Details and references
- CVSS 3.1
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
- Severity from
- GitHub (reviewed advisory)
- Weakness
- CWE-116
- Also known as
- CVE-2024-34510, PYSEC-2024-255
More Gradio advisories
All Gradio| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Jun 62024 | Server-Side Request Forgery in gradio | High8.6 | No fix yet |
| Jun 42024 | Gradio: command injection | Critical9.1 | 4.29.0 |
| May 212024 | Gradio applications running locally vulnerable to 3rd party websites accessing routes and uploading files | Medium4.3 | 4.19.2 |
| May 52024 | Gradio's Component Server does not properly consider` _is_server_fn` for functions | Medium6.5 | 4.13.0 |
| Apr 162024 | gradio vulnerable to Path Traversal | High7.5 | 4.13.0 |
| Apr 162024 | gradio Server-Side Request Forgery vulnerability | Medium6.5 | 4.10.0 |