GradioGHSA-v4q9-qgqf-7jwp
Gradio arbitrary file upload vulnerability
Medium4.8CVE-2023-41626 · Published Sep 16, 2023 · updated Jul 7, 2026
Gradio v3.27.0 was discovered to contain an arbitrary file upload vulnerability via the `/upload` interface.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| gradio PyPI | <= 3.27.0 | No fix yet |
Details and references
- CVSS 3.1
- CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N
- Severity from
- GitHub (reviewed advisory)
- Weakness
- CWE-434
- Also known as
- CVE-2023-41626, PYSEC-2026-1422
More Gradio advisories
All Gradio| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Mar 272024 | gradio Server-Side Request Forgery vulnerability | High7.3 | 4.18.0 |
| Feb 222024 | Gradio apps vulnerable to timing attacks to guess password | Medium5.9 | 4.19.2 |
| Feb 62024 | Gradio Path Traversal vulnerability | High7.5 | 4.9.0 |
| Dec 212023 | Gradio makes the `/file` secure against file traversal and server-side request forgery attacks | High8.6 | 4.11.0 |
| Dec 142023 | Gradio Exposure of Sensitive Information to an Unauthorized Actor vulnerability | Critical9.6 | 4.14.0 |
| Jun 92023 | Gradio vulnerable to arbitrary file read and proxying of arbitrary URLs | Medium7.3 | 3.34.0 |