Database/AI/ML frameworks & serving
Gradio: Lack of path filtering
CVSS 7.3CVE-2023-34239AI/ML frameworks & servingcurated
Impact
Lack of path filtering → arbitrary file read from the host
Who can reach it
Unauthenticated network to the demo
What to do
Upgrade; a Gradio demo runs with the tenant's full container filesystem access
References
Related entries
- Gradio: SSRF in the `/proxy` routeCVE-2024-2206 · GradioMedium
- Gradio: Code injection via `gradio/component_meta.py`CVE-2024-39236 · GradioCritical
- Gradio: SSRF from the file-upload/proxy pathCVE-2024-47167 · GradioCritical
- Gradio: Remotely triggerable local file include via a JSON value in an API requestCVE-2024-0964 · GradioCritical
- Gradio: CORS origin validation bypassCVE-2024-47084 · GradioHigh
- Gradio: Command injectionCVE-2023-6572 · GradioHigh
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.