CVE-2023-51449
Gradio is an open-source Python package that allows you to quickly build a demo or web application for your machine learning model, API, or any arbitary Python function.
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 28.3%, higher than 98% of all known CVEs. Patch or mitigate before the next change window.
Description
Gradio is an open-source Python package that allows you to quickly build a demo or web application for your machine learning model, API, or any arbitary Python function. Versions of `gradio` prior to 4.11.0 contained a vulnerability in the `/file` route which made them susceptible to file traversal attacks in which an attacker could access arbitrary files on a machine running a Gradio app with a public URL (e.g. if the demo was created with `share=True`, or on Hugging Face Spaces) if they knew the path of files to look for. This issue has been patched in version 4.11.0.
- CVSS 3.1
- 7.5 HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
- EPSS
- 28.34% probability · 98th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-22
- Affected
- gradio project/gradio
- Source
- security-advisories@github.com
References
- https://github.com/gradio-app/gradio/commit/1b9d4234d6c25ef250d882c7b90e1f4039ed2d76Patch
- https://github.com/gradio-app/gradio/commit/7ba8c5da45b004edd12c0460be9222f5b5f5f055Patch
- https://github.com/gradio-app/gradio/security/advisories/GHSA-6qm2-wpxq-7qh2Third Party Advisory
- https://github.com/gradio-app/gradio/commit/1b9d4234d6c25ef250d882c7b90e1f4039ed2d76Patch
- https://github.com/gradio-app/gradio/commit/7ba8c5da45b004edd12c0460be9222f5b5f5f055Patch
- https://github.com/gradio-app/gradio/security/advisories/GHSA-6qm2-wpxq-7qh2Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.