© 2025-2026 PySpect
First version without a known vulnerability: 6.16.0
Gradio before 6.16.0 contain a path traversal vulnerability in the FileExplorer component's preprocess() method that allows unauthenticated attackers to escape the configured root directory by supplying path segments containing directory traversal sequences or absolute paths. Attackers can provide crafted path segments that cause os.path.join to discard the root_dir prefix entirely, resulting in arbitrary file read or exposure of sensitive files outside the intended directory.
Fixed in: 6.16.0
Gradio: Audio cache key ignores metadata when saving numpy audio outputs
Fixed in: 6.15.1
Gradio contains a cookie injection vulnerability
Fixed in: 6.15.0
Gradio has SSRF via Malicious `proxy_url` Injection in `gr.load()` Config Processing
Fixed in: 6.6.0
Gradio has an Open Redirect in its OAuth Flow
Fixed in: 6.6.0
Gradio is Vulnerable to Absolute Path Traversal on Windows with Python 3.13+
Fixed in: 6.7.0
Gradio: Mocked OAuth Login Exposes Server Credentials and Uses Hardcoded Session Secret
Fixed in: 6.6.0
Gradio Allows Unauthorized File Copy via Path Manipulation
Fixed in: 5.31.0
Gradio CORS Origin Validation Bypass Vulnerability
Gradio DOS in multipart boundry while uploading the file
Gradio Vulnerable to Open Redirect
Gradio Path Traversal vulnerability
Gradio Vulnerable to Denial of Service (DoS) via Crafted Zip Bomb
Gradio Vulnerable to Arbitrary File Deletion
Gradio Vulnerable to Denial of Service (DoS) via Crafted HTTP Request
Gradio Blocked Path ACL Bypass Vulnerability
Fixed in: 5.11.0, 5.6.0
Gradio vulnerable to arbitrary file read with File and UploadButton components
Fixed in: 5.5.0
gradio Server Side Request Forgery vulnerability
Gradio's dropdown component pre-process step does not limit the values to those in the dropdown list
Fixed in: 5.0.0
Gradio has an XSS on every Gradio server via upload of HTML files, JS files, or SVG files
Fixed in: 5.0.0
Gradio uses insecure communication between the FRP client and server
Fixed in: 5.0.0
Gradio has a race condition in update_root_in_config may redirect user traffic
Fixed in: 5.0.0
Gradio performs a non-constant-time comparison when comparing hashes
Fixed in: 4.44.0
Gradio has several components with post-process steps allow arbitrary file leaks
Fixed in: 5.0.0
Gradio lacks integrity checking on the downloaded FRP client
Fixed in: 5.0.0
In Gradio, the `enable_monitoring` flag set to `False` does not disable monitoring
Fixed in: 4.44.0
Gradio vulnerable to SSRF in the path parameter of /queue/join
Fixed in: 5.0.0
Gradio has a one-level read path traversal in `/custom_component`
Fixed in: 4.44.0
Gradio's CORS origin validation accepts the null origin
Fixed in: 5.0.0
Gradio's `is_in_or_equal` function may be bypassed
Fixed in: 5.0.0
Gradios's CORS origin validation is not performed when the request has a cookie
Fixed in: 4.44.0
Gradio allows users to access arbitrary files
Fixed in: 4.19.2
Gradio v4.36.1 was discovered to contain a code injection vulnerability via the component /gradio/component_meta.py. This vulnerability is triggered via a crafted input. NOTE: the supplier disputes this because the report is about a user attacking himself.
Open redirect in gradio
Local file inclusion in gradio
Fixed in: 4.31.3, ee1e2942e0a1ae84a08a05464e41c8108a03fa9c, 4.31.4
Server-Side Request Forgery in gradio
A command injection vulnerability exists in the gradio-app/gradio repository, specifically within the 'test-functional.yml' workflow. The vulnerability arises due to improper neutralization of special elements used in a command, allowing for unauthorized modification of the base repository or secrets exfiltration. The issue affects versions up to and including '@gradio/video@0.6.12'. The flaw is present in the workflow's handling of GitHub context information, where it echoes the full name of the head repository, the head branch, and the workflow reference without adequate sanitization. This could potentially lead to the exfiltration of sensitive secrets such as 'GITHUB_TOKEN', 'COMMENT_TOKEN', and 'CHROMATIC_PROJECT_TOKEN'.
Fixed in: 4.29.0
Gradio applications running locally vulnerable to 3rd party websites accessing routes and uploading files
Fixed in: 4.19.2
Gradio's Component Server does not properly consider` _is_server_fn` for functions
Fixed in: 4.13.0
Gradio allows credential leakage on Windows
Fixed in: 4.20.0
gradio vulnerable to Path Traversal
Fixed in: 4.13.0
gradio Server-Side Request Forgery vulnerability
Fixed in: 4.10.0
gradio Server-Side Request Forgery vulnerability
Fixed in: 4.18.0
Gradio apps vulnerable to timing attacks to guess password
Fixed in: 4.19.2
Gradio Path Traversal vulnerability
Fixed in: 4.9.0
Gradio makes the `/file` secure against file traversal and server-side request forgery attacks
Fixed in: 4.11.0, 1b9d4234d6c25ef250d882c7b90e1f4039ed2d76, 7ba8c5da45b004edd12c0460be9222f5b5f5f055
Gradio Exposure of Sensitive Information to an Unauthorized Actor vulnerability
Fixed in: 4.14.0, 5b5af1899dd98d63e1f9b48a93601c2db1f56520
Gradio arbitrary file upload vulnerability
Gradio vulnerable to arbitrary file read and proxying of arbitrary URLs
Fixed in: 3.34.0
Update share links to use FRP instead of SSH tunneling
Fixed in: 3.13.1
Improper Neutralization of Formula Elements in a CSV File in Gradio Flagging
Fixed in: 2.8.11, 80fea89117358ee105973453fdc402398ae20239
Files on the host computer can be accessed from the Gradio interface
Fixed in: 2.5.0, 41bd3645bdb616e1248b2167ca83636a2653f781