github.com
https://github.com/gradio-app/gradio CVE-2024-10648
HIGH
Path Traversal in gradio-app/gradio
Record summary
CVE-2024-10648 has a selected CVSS score of 8.2 (high).
Description
A path traversal vulnerability exists in the Gradio Audio component of gradio-app/gradio, as of version git 98cbcae. This vulnerability allows an attacker to control the format of the audio file, leading to arbitrary file content deletion. By manipulating the output format, an attacker can reset any file to an empty file, causing a denial of service (DOS) on the server.
Description source: CVE List
Exploitation context
CISA SSVC decision
ExploitationPoC
AutomatableYes
Technical impactPartial
CISA Coordinator · SSVC 2.0.3 · Evaluated Mar 20, 2025 · Source: CVE List
Affected products and versions
2| Product | Source | Version range | Status |
|---|---|---|---|
gradio-app/gradioBrowse gradio-app / gradio-app/gradio | CVE List | Through latest | affected |
gradioBrowse PyPI / gradio | GitHub Advisory | 4.0.0 to ≤ 5.0.0b2 | affected |
References
4github.com
https://github.com/gradio-app/gradio/blame/98cbcaef827de7267462ccba180c7b2ffb1e825d/gradio/processing_utils.py huntr.com
https://huntr.com/bounties/667d664d-8189-458c-8ed7-483fe8f33c76 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2024-10648