Record summary

CVE-2024-10648 has a selected CVSS score of 8.2 (high).

Description

A path traversal vulnerability exists in the Gradio Audio component of gradio-app/gradio, as of version git 98cbcae. This vulnerability allows an attacker to control the format of the audio file, leading to arbitrary file content deletion. By manipulating the output format, an attacker can reset any file to an empty file, causing a denial of service (DOS) on the server.

Description source: CVE List

Exploitation context

CISA SSVC decision

ExploitationPoC
AutomatableYes
Technical impactPartial

CISA Coordinator · SSVC 2.0.3 · Evaluated Mar 20, 2025 · Source: CVE List

Affected products and versions

2
ProductSourceVersion rangeStatus
CVE ListThrough latestaffected
GitHub Advisory4.0.0 to ≤ 5.0.0b2affected

References

4