github.com
https://github.com/gradio-app/gradio CVE-2024-0964
CRITICAL
LFI in Gradio
Record summary
CVE-2024-0964 has a selected CVSS score of 9.4 (critical).
Description
A local file include could be remotely triggered in Gradio due to a vulnerable user-supplied JSON value in an API request.
Description source: CVE List
Exploitation context
CISA SSVC decision
ExploitationPoC
AutomatableYes
Technical impactPartial
CISA Coordinator · SSVC 2.0.3 · Evaluated Feb 6, 2024 · Source: CVE List
Affected products and versions
2| Product | Source | Version range | Status |
|---|---|---|---|
gradio-app/gradioBrowse gradio-app / gradio-app/gradioDefault status: unknown | CVE List | Before x | affected |
| Through * | affected | ||
gradioBrowse PyPI / gradio | GitHub Advisory | Before 4.9.0 · Fixed in 4.9.0 | affected |
References
5github.com
https://github.com/gradio-app/gradio/commit/d76bcaaaf0734aaf49a680f94ea9d4d22a602e70 github.com
https://github.com/pypa/advisory-database/tree/main/vulns/gradio/PYSEC-2024-261.yaml huntr.com
https://huntr.com/bounties/25e25501-5918-429c-8541-88832dfd3741 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2024-0964