Database/AI/ML frameworks & serving
Gradio: Lack of path filtering
CVE-2023-34239AI/ML frameworks & servingcurated
Impact
Lack of path filtering → arbitrary file read from the host
Who can reach it
Unauthenticated network to the demo
What to do
Upgrade; a Gradio demo runs with the tenant's full container filesystem access
References
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.