QID 996437
Date Published: 2023-12-26
QID 996437: Python (Pip) Security Update for gradio (GHSA-6qm2-wpxq-7qh2)
Older versions of gradio contained a vulnerability in the /file route which made them susceptible to file traversal attacks in which an attacker could access arbitrary files on a machine running a Gradio app with a public URL (e.g. if the demo was created with share=True, or on Hugging Face Spaces) if they knew the path of files to look for.
Successful exploitation of this vulnerability could lead to a security breach or could affect integrity, availability, and confidentiality.
Solution
Refer to Github security advisory GHSA-6qm2-wpxq-7qh2 for updates and patch information.
Vendor References
- GHSA-6qm2-wpxq-7qh2 -
github.com/advisories/GHSA-6qm2-wpxq-7qh2
CVEs related to QID 996437
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-6qm2-wpxq-7qh2 | gradio |
|