Gradio's dropdown component pre-process step does not limit the values to those in the dropdown list
Modified: 9/10/2026
package
pkg:pypi/gradio
Gradio's dropdown component pre-process step does not limit the values to those in the dropdown list
Modified: 9/10/2026
Gradio uses insecure communication between the FRP client and server
Modified: 1/21/2025
Gradio's Component Server does not properly consider` _is_server_fn` for functions
Modified: 9/10/2026
Gradio has a one-level read path traversal in `/custom_component`
Modified: 1/21/2025
Gradio is Vulnerable to Absolute Path Traversal on Windows with Python 3.13+
Modified: 6/6/2026
Gradios's CORS origin validation is not performed when the request has a cookie
Modified: 1/21/2025
gradio Server Side Request Forgery vulnerability
Modified: 9/10/2026
Gradio vulnerable to arbitrary file read and proxying of arbitrary URLs
Modified: 9/10/2026
Update share links to use FRP instead of SSH tunneling
Modified: 9/10/2026
Gradio applications running locally vulnerable to 3rd party websites accessing routes and uploading files
Modified: 9/10/2026
Gradio has several components with post-process steps allow arbitrary file leaks
Modified: 1/21/2025
Gradio vulnerable to SSRF in the path parameter of /queue/join
Modified: 1/21/2025
Gradio DOS in multipart boundry while uploading the file
Modified: 7/7/2026
Gradio: Audio cache key ignores metadata when saving numpy audio outputs
Modified: 7/14/2026
Gradio makes the `/file` secure against file traversal and server-side request forgery attacks
Modified: 9/10/2026
Local file inclusion in gradio
Modified: 10/16/2025
Gradio's `is_in_or_equal` function may be bypassed
Modified: 1/21/2025
Gradio contains a cookie injection vulnerability
Modified: 7/13/2026
Gradio Vulnerable to Open Redirect
Modified: 7/7/2026
Gradio Vulnerable to Denial of Service (DoS) via Crafted Zip Bomb
Modified: 7/7/2026
Gradio's CORS origin validation accepts the null origin
Modified: 1/21/2025
Gradio lacks integrity checking on the downloaded FRP client
Modified: 1/21/2025
Gradio Allows Unauthorized File Copy via Path Manipulation
Modified: 6/5/2026
Server-Side Request Forgery in gradio
Modified: 9/10/2026
Gradio Path Traversal vulnerability
Modified: 5/19/2026
Improper Neutralization of Formula Elements in a CSV File in Gradio Flagging
Modified: 11/8/2023
Open redirect in gradio
Modified: 9/10/2026
gradio vulnerable to Path Traversal
Modified: 9/10/2026
Gradio Exposure of Sensitive Information to an Unauthorized Actor vulnerability
Modified: 9/10/2026
Gradio has an XSS on every Gradio server via upload of HTML files, JS files, or SVG files
Modified: 1/21/2025
Gradio: Mocked OAuth Login Exposes Server Credentials and Uses Hardcoded Session Secret
Modified: 6/5/2026
In Gradio, the `enable_monitoring` flag set to `False` does not disable monitoring
Modified: 1/21/2025
Gradio apps vulnerable to timing attacks to guess password
Modified: 9/10/2026
Gradio Blocked Path ACL Bypass Vulnerability
Modified: 6/5/2026
Gradio performs a non-constant-time comparison when comparing hashes
Modified: 1/21/2025
Gradio has SSRF via Malicious `proxy_url` Injection in `gr.load()` Config Processing
Modified: 6/6/2026
Gradio allows users to access arbitrary files
Modified: 6/29/2026
Gradio has an Open Redirect in its OAuth Flow
Modified: 6/6/2026
Gradio Vulnerable to Arbitrary File Deletion
Modified: 7/7/2026
Gradio Path Traversal vulnerability
Modified: 7/7/2026
gradio Server-Side Request Forgery vulnerability
Modified: 9/10/2026
gradio Server-Side Request Forgery vulnerability
Modified: 9/10/2026
Gradio vulnerable to arbitrary file read with File and UploadButton components
Modified: 6/5/2026
Files on the host computer can be accessed from the Gradio interface
Modified: 7/8/2026
Gradio allows credential leakage on Windows
Modified: 6/17/2025
Gradio Vulnerable to Denial of Service (DoS) via Crafted HTTP Request
Modified: 7/7/2026
Gradio arbitrary file upload vulnerability
Modified: 7/7/2026
Gradio CORS Origin Validation Bypass Vulnerability
Modified: 7/7/2026
Gradio has a race condition in update_root_in_config may redirect user traffic
Modified: 1/21/2025
Modified: 11/8/2023
Modified: 11/8/2023
Modified: 11/8/2023
Modified: 1/17/2024
Modified: 6/10/2026
Modified: 11/8/2023
Modified: 6/10/2026
Modified: 1/19/2025
Modified: 1/19/2025
Modified: 1/19/2025
Modified: 1/19/2025
Modified: 1/19/2025
Modified: 1/19/2025
Modified: 1/19/2025
Modified: 1/19/2025
Modified: 1/19/2025
Modified: 1/19/2025
Modified: 1/19/2025
Modified: 1/19/2025
Modified: 6/10/2026
Modified: 6/10/2026
Modified: 5/21/2026
Modified: 5/20/2026
Modified: 7/13/2026
Modified: 5/20/2026
Modified: 5/20/2026
Gradio's Component Server does not properly consider` _is_server_fn` for functions
Modified: 7/7/2026
gradio Server Side Request Forgery vulnerability
Modified: 7/7/2026
Gradio applications running locally vulnerable to 3rd party websites accessing routes and uploading files
Modified: 7/7/2026
Gradio DOS in multipart boundry while uploading the file
Modified: 7/7/2026
Gradio Vulnerable to Open Redirect
Modified: 7/7/2026
Gradio Vulnerable to Denial of Service (DoS) via Crafted Zip Bomb
Modified: 7/7/2026
Server-Side Request Forgery in gradio
Modified: 7/7/2026
Open redirect in gradio
Modified: 7/7/2026
gradio vulnerable to Path Traversal
Modified: 7/7/2026
Gradio apps vulnerable to timing attacks to guess password
Modified: 7/7/2026
Gradio Vulnerable to Arbitrary File Deletion
Modified: 7/7/2026
Gradio Path Traversal vulnerability
Modified: 7/7/2026
gradio Server-Side Request Forgery vulnerability
Modified: 7/7/2026
gradio Server-Side Request Forgery vulnerability
Modified: 7/7/2026
Gradio Vulnerable to Denial of Service (DoS) via Crafted HTTP Request
Modified: 7/7/2026
Gradio arbitrary file upload vulnerability
Modified: 7/7/2026
Gradio CORS Origin Validation Bypass Vulnerability
Modified: 7/7/2026
Modified: 7/23/2026
Modified: 7/13/2026
Modified: 7/13/2026
Gradio allows users to access arbitrary files
Modified: 7/1/2026
Modified: 5/20/2026
Modified: 5/20/2026
Modified: 5/20/2026
Modified: 5/20/2026