Known Vulnerabilities for Gradio by Gradio-app
Listed below are 8 of the newest known vulnerabilities associated with "Gradio" by "Gradio-app".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-82637 json | browser-use web-ui versions 2.0.0 through 3.0.0 fail to validate browser settings paths in run_agent_task, allowing attackers... | Not Provided | 2026-08-30 | 2026-09-02 |
| CVE-2026-82275 json | Qwen-Agent through 0.0.34 contains a path traversal vulnerability in the document parser that fails to restrict file access t... | Not Provided | 2026-08-28 | 2026-08-31 |
| CVE-2026-82268 json | Qwen-Agent through 0.0.34 contains a server-side request forgery vulnerability in the document parsing path that treats calle... | Not Provided | 2026-08-28 | 2026-08-28 |
| CVE-2026-63766 json | GPT-SoVITS through 20250606v2pro contains an OS command injection vulnerability in webui.py where ASR, slice, denoise, and uv... | Not Provided | 2026-07-20 | 2026-07-21 |
| CVE-2026-59806 json | Gradio before 6.20.0 contains an open redirect and server-side request forgery vulnerability that allows attackers to redirec... | Not Provided | 2026-07-08 | 2026-07-09 |
| CVE-2026-49119 json | Gradio before 6.16.0 contain a path traversal vulnerability in the FileExplorer component's preprocess() method that allows u... | Not Provided | 2026-07-01 | 2026-07-14 |
| CVE-2026-48545 json | Gradio before version 6.15.0 contains a cookie injection vulnerability that allows remote attackers to perform cross-Space se... | Not Provided | 2026-05-27 | 2026-07-14 |
| CVE-2026-43624 json | F5-TTS through version 1.1.20 contains a path traversal vulnerability in the finetune Gradio handlers that allows unauthentic... | Not Provided | 2026-06-01 | 2026-07-14 |