VDB
EN
MEDIUM 6.5

GHSA-3gf9-wv65-gwh9

gradio Server Side Request Forgery vulnerability

상세

In gradio <=4.42.0, the gr.DownloadButton function has a hidden server-side request forgery (SSRF) vulnerability. The reason is that within the save_url_to_cache function, there are no restrictions on the URL, which allows access to local target resources. This can lead to the download of local resources and sensitive information.

이 버전이 영향받나요?

사용 중인 패키지 버전을 입력하면 즉시 평가합니다.

영향 패키지

PyPI / gradio
최초 영향 버전: 0

No fixed version published yet for gradio (pip). Pin to a known-safe version or switch to an alternative.

참고