MEDIUM4.8
PYSEC-2026-1422
Gradio arbitrary file upload vulnerability
Details
Gradio v3.27.0 was discovered to contain an arbitrary file upload vulnerability via the `/upload` interface.
Are you affected?
Enter the version of the package you're using.
Affected packages
PyPI/gradio
Introduced in:
0No fixed version published yet for gradio (pip). Pin to a known-safe version or switch to an alternative.