Skip to content
GradioGHSA-v4q9-qgqf-7jwp

Gradio arbitrary file upload vulnerability

Medium4.8CVE-2023-41626 · Published Sep 16, 2023 · updated Jul 7, 2026

Gradio v3.27.0 was discovered to contain an arbitrary file upload vulnerability via the `/upload` interface.

GitHub advisory

Affected versions

PackageAffectedFixed in
gradio
PyPI
<= 3.27.0No fix yet
Details and references
CVSS 3.1
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N
Severity from
GitHub (reviewed advisory)
Weakness
CWE-434
Also known as
CVE-2023-41626, PYSEC-2026-1422

More Gradio advisories

All Gradio
Advisory
gradio Server-Side Request Forgery vulnerability
High7.3Mar 27, 2024
Gradio apps vulnerable to timing attacks to guess password
Medium5.9Feb 22, 2024
Gradio Path Traversal vulnerability
High7.5Feb 6, 2024
Gradio makes the `/file` secure against file traversal and server-side request forgery attacks
High8.6Dec 21, 2023
Gradio Exposure of Sensitive Information to an Unauthorized Actor vulnerability
Critical9.6Dec 14, 2023
Gradio vulnerable to arbitrary file read and proxying of arbitrary URLs
Medium7.3Jun 9, 2023

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.