Skip to content

Gradio security advisories

52 advisories · 4 critical or high in 12 months · latest Jul 1

52 advisories

DateAdvisory
Jul 1Gradio before 6.16.0 contain a path traversal vulnerability in the FileExplorer component's preprocess() method that allows unauthenticated attackers to escape the configured root directory by supplying path segments containing directory traversal sequences or absolute paths. Attackers can provide c
CVE-2026-49119High7.5fixed in 6.16.0
Jun 4Gradio: Audio cache key ignores metadata when saving numpy audio outputs
CVE-2026-10783Low2.5fixed in 6.15.1
May 27Gradio contains a cookie injection vulnerability
CVE-2026-48545High6.8fixed in 6.15.0
Mar 1Gradio has SSRF via Malicious `proxy_url` Injection in `gr.load()` Config Processing
CVE-2026-28416High8.2fixed in 6.6.0
Mar 1Gradio has an Open Redirect in its OAuth Flow
CVE-2026-28415Medium4.3fixed in 6.6.0
Mar 1Gradio is Vulnerable to Absolute Path Traversal on Windows with Python 3.13+
CVE-2026-28414High7.5fixed in 6.7.0
Mar 1Gradio: Mocked OAuth Login Exposes Server Credentials and Uses Hardcoded Session Secret
CVE-2026-27167Low0.0fixed in 6.6.0
May 292025Gradio Allows Unauthorized File Copy via Path Manipulation
CVE-2025-48889Medium5.3fixed in 5.31.0
May 292025Gradio CORS Origin Validation Bypass Vulnerability
CVE-2025-5320Low3.7no fix yet
Mar 202025Gradio DOS in multipart boundry while uploading the file
CVE-2024-8966High7.5no fix yet
Mar 202025Gradio Vulnerable to Open Redirect
CVE-2024-8021Medium5.4no fix yet
Mar 202025Gradio Path Traversal vulnerability
CVE-2024-12217Medium5.3no fix yet
Mar 202025Gradio Vulnerable to Denial of Service (DoS) via Crafted Zip Bomb
CVE-2024-10569High7.5no fix yet
Mar 202025Gradio Vulnerable to Arbitrary File Deletion
CVE-2024-10648High8.2no fix yet
Mar 202025Gradio Vulnerable to Denial of Service (DoS) via Crafted HTTP Request
CVE-2024-10624High7.5no fix yet
Jan 142025Gradio Blocked Path ACL Bypass Vulnerability
CVE-2025-23042Criticalfixed in 5.11.0
Nov 62024Gradio vulnerable to arbitrary file read with File and UploadButton components
CVE-2024-51751Medium0.0fixed in 5.5.0
Nov 52024gradio Server Side Request Forgery vulnerability
CVE-2024-48052Medium6.5no fix yet
Oct 102024Gradio's dropdown component pre-process step does not limit the values to those in the dropdown list
GHSA-26jh-r8g2-6fprLow5.3fixed in 5.0.0
Oct 102024Gradio has an XSS on every Gradio server via upload of HTML files, JS files, or SVG files
CVE-2024-47872Medium5.4fixed in 5.0.0
Oct 102024Gradio uses insecure communication between the FRP client and server
CVE-2024-47871High8.1fixed in 5.0.0
Oct 102024Gradio has a race condition in update_root_in_config may redirect user traffic
CVE-2024-47870High7.0fixed in 5.0.0
Oct 102024Gradio performs a non-constant-time comparison when comparing hashes
CVE-2024-47869Medium3.7fixed in 4.44.0
Oct 102024Gradio has several components with post-process steps allow arbitrary file leaks
CVE-2024-47868Medium5.3fixed in 5.0.0
Oct 102024Gradio lacks integrity checking on the downloaded FRP client
CVE-2024-47867High7.5fixed in 5.0.0
Oct 102024In Gradio, the `enable_monitoring` flag set to `False` does not disable monitoring
CVE-2024-47168Low4.3fixed in 4.44.0
Oct 102024Gradio vulnerable to SSRF in the path parameter of /queue/join
CVE-2024-47167Medium7.2fixed in 5.0.0
Oct 102024Gradio has a one-level read path traversal in `/custom_component`
CVE-2024-47166Medium5.3fixed in 4.44.0
Oct 102024Gradio's CORS origin validation accepts the null origin
CVE-2024-47165Medium5.4fixed in 5.0.0
Oct 102024Gradio's `is_in_or_equal` function may be bypassed
CVE-2024-47164Medium6.5fixed in 5.0.0
Oct 102024Gradios's CORS origin validation is not performed when the request has a cookie
CVE-2024-47084High8.8fixed in 4.44.0
Sep 252024Gradio allows users to access arbitrary files
CVE-2024-1728Critical8.1fixed in 4.19.2
Jul 12024Gradio v4.36.1 was discovered to contain a code injection vulnerability via the component /gradio/component_meta.py. This vulnerability is triggered via a crafted input. NOTE: the supplier disputes this because the report is about a user attacking himself.
CVE-2024-39236Critical9.8no fix yet
Jun 222024Open redirect in gradio
CVE-2024-4940Medium5.4no fix yet
Jun 62024Local file inclusion in gradio
CVE-2024-4941High7.5fixed in 4.31.3
Jun 62024Server-Side Request Forgery in gradio
CVE-2024-4325High8.6no fix yet
Jun 42024A command injection vulnerability exists in the gradio-app/gradio repository, specifically within the 'test-functional.yml' workflow. The vulnerability arises due to improper neutralization of special elements used in a command, allowing for unauthorized modification of the base repository or secret
CVE-2024-4253Critical9.1fixed in 4.29.0
May 212024Gradio applications running locally vulnerable to 3rd party websites accessing routes and uploading files
CVE-2024-1727Medium4.3fixed in 4.19.2
May 52024Gradio's Component Server does not properly consider` _is_server_fn` for functions
CVE-2024-34511Medium6.5fixed in 4.13.0
May 52024Gradio allows credential leakage on Windows
CVE-2024-34510High7.5fixed in 4.20.0
Apr 162024gradio vulnerable to Path Traversal
CVE-2024-1561High7.5fixed in 4.13.0
Apr 162024gradio Server-Side Request Forgery vulnerability
CVE-2024-1183Medium6.5fixed in 4.10.0
Mar 272024gradio Server-Side Request Forgery vulnerability
CVE-2024-2206High7.3fixed in 4.18.0
Feb 222024Gradio apps vulnerable to timing attacks to guess password
CVE-2024-1729Medium5.9fixed in 4.19.2
Feb 62024Gradio Path Traversal vulnerability
CVE-2024-0964High7.5fixed in 4.9.0
Dec 212023Gradio makes the `/file` secure against file traversal and server-side request forgery attacks
CVE-2023-51449High8.6fixed in 4.11.0
Dec 142023Gradio Exposure of Sensitive Information to an Unauthorized Actor vulnerability
CVE-2023-6572Critical9.6fixed in 4.14.0
Sep 162023Gradio arbitrary file upload vulnerability
CVE-2023-41626Medium4.8no fix yet
Jun 92023Gradio vulnerable to arbitrary file read and proxying of arbitrary URLs
CVE-2023-34239Medium7.3fixed in 3.34.0
Feb 232023Update share links to use FRP instead of SSH tunneling
CVE-2023-25823Medium5.4fixed in 3.13.1
Mar 182022Improper Neutralization of Formula Elements in a CSV File in Gradio Flagging
CVE-2022-24770High8.8fixed in 2.8.11
Jan 212022Files on the host computer can be accessed from the Gradio interface
CVE-2021-43831Critical8.3fixed in 2.5.0
About Gradio

Web apps and demos for models.

Packages watched: gradio (PyPI).

Hugging Face elsewhere on fru.dev: Acquisitions · Paydays · Releases · Repos · Trending

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.