Skip to content
GradioPYSEC-2024-321

A command injection vulnerability exists in the gradio-app/gradio repository, specifically within the 'test-functional.yml' workflow. The vulnerability arises due to improper neutralization of special elements used in a command, allowing for unauthorized modification of the base repository or secret

Critical9.1CVE-2024-4253 · Published Jun 4, 2024 · updated Jul 13, 2026

Source advisory

Affected versions

PackageAffectedFixed in
gradio
PyPI
< 4.29.04.29.0
Details and references

A command injection vulnerability exists in the gradio-app/gradio repository, specifically within the 'test-functional.yml' workflow. The vulnerability arises due to improper neutralization of special elements used in a command, allowing for unauthorized modification of the base repository or secrets exfiltration. The issue affects versions up to and including '@gradio/video@0.6.12'. The flaw is present in the workflow's handling of GitHub context information, where it echoes the full name of the head repository, the head branch, and the workflow reference without adequate sanitization. This could potentially lead to the exfiltration of sensitive secrets such as 'GITHUB_TOKEN', 'COMMENT_TOKEN', and 'CHROMATIC_PROJECT_TOKEN'.

CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Severity from
the CVSS score
Also known as
CVE-2024-4253

More Gradio advisories

All Gradio
DateAdvisory
Jun 62024Local file inclusion in gradio
CVE-2024-4941High7.5fixed in 4.31.3
Jun 62024Server-Side Request Forgery in gradio
CVE-2024-4325High8.6no fix yet
May 212024Gradio applications running locally vulnerable to 3rd party websites accessing routes and uploading files
CVE-2024-1727Medium4.3fixed in 4.19.2
Jun 222024Open redirect in gradio
CVE-2024-4940Medium5.4no fix yet
Jul 12024Gradio v4.36.1 was discovered to contain a code injection vulnerability via the component /gradio/component_meta.py. This vulnerability is triggered via a crafted input. NOTE: the supplier disputes this because the report is about a user attacking himself.
CVE-2024-39236Critical9.8no fix yet
May 52024Gradio's Component Server does not properly consider` _is_server_fn` for functions
CVE-2024-34511Medium6.5fixed in 4.13.0

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.