CVE-2023-34239

HIGH

Gradio < 3.34.0 - Path Traversal and Server-Side Request Forgery

Title source: llm
STIX 2.1

Description

Gradio is an open-source Python library that is used to build machine learning and data science. Due to a lack of path filtering Gradio does not properly restrict file access to users. Additionally Gradio does not properly restrict the what URLs are proxied. These issues have been addressed in version 3.34.0. Users are advised to upgrade. There are no known workarounds for this vulnerability.

References (3)

Core 3

Scores

CVSS v3 7.3
EPSS 0.0065
EPSS Percentile 46.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact total

Details

CWE
CWE-20
Status published
Products (2)
gradio_project/gradio < 3.34.0
pypi/gradio 0 - 3.34.0PyPI
Published Jun 08, 2023
Tracked Since Feb 18, 2026