<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Wed, 07 Oct 2026 15:23:24 +0000</lastBuildDate>
    <item>
      <title>CVE-2025-48889 — Gradio Allows Unauthorized File Copy via Path Manipulation</title>
      <link>https://cve.radiocsirt.org/vuln/cve-2025-48889</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; gradio-app gradio&lt;/p&gt;
&lt;p&gt;Gradio is an open-source Python package that allows quick building of demos and web application for machine learning models, API, or any arbitrary Python function. Prior to version 5.31.0, an arbitrary file copy vulnerability in Gradio&amp;#39;s flagging feature allows unauthenticated attackers to copy any readable file from the server&amp;#39;s filesystem. While attackers can&amp;#39;t read these copied files, they can cause DoS by copying large files (like /dev/urandom) to fill disk space. This issue has been patched in version 5.31.0.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; gradio-app gradio&lt;/p&gt;
&lt;p&gt;Gradio is an open-source Python package that allows quick building of demos and web application for machine learning models, API, or any arbitrary Python function. Prior to version 5.31.0, an arbitrary file copy vulnerability in Gradio&amp;#39;s flagging feature allows unauthenticated attackers to copy any readable file from the server&amp;#39;s filesystem. While attackers can&amp;#39;t read these copied files, they can cause DoS by copying large files (like /dev/urandom) to fill disk space. This issue has been patched in version 5.31.0.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cve-2025-48889</guid>
    </item>
    <item>
      <title>GHSA-8jw3-6x8j-v96g — Gradio Allows Unauthorized File Copy via Path Manipulation</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-8jw3-6x8j-v96g</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: gradio&lt;/p&gt;
&lt;p&gt;An arbitrary file copy vulnerability in Gradio&amp;#39;s flagging feature allows unauthenticated attackers to copy any readable file from the server&amp;#39;s filesystem. While attackers can&amp;#39;t read these copied files, they can cause DoS by copying large files (like /dev/urandom) to fill disk space.&lt;/p&gt;
&lt;p&gt;### Description
The flagging component doesn&amp;#39;t properly validate file paths before copying files. Attackers can send specially crafted requests to the `/gradio_api/run/predict` endpoint to trigger these file copies.&lt;/p&gt;
&lt;p&gt;**Source**: User-controlled `path` parameter in the flagging functionality JSON payload  
**Sink**: `shutil.copy` operation in `FileData._copy_to_dir()` method&lt;/p&gt;
&lt;p&gt;The vulnerable code flow:
1. A JSON payload is sent to the `/gradio_api/run/predict` endpoint
2. The `path` field within `FileData` object can reference any file on the system
3. When processing this request, the `Component.flag()` method creates a `GradioDataModel` object
4. The `FileData._copy_to_dir()` method uses this path without proper validation:&lt;/p&gt;
&lt;p&gt;```python
def _copy_to_dir(self, dir: str) -&amp;gt; FileData:
    pathlib.Path(dir).mkdir(exist_ok=True)
    new_obj = dict(self)&lt;/p&gt;
&lt;p&gt;if not self.path:
        raise ValueError(&amp;#34;Source file path is not set&amp;#34;)
    new_name = shutil.copy(self.path, dir)  # vulnerable sink
    new_obj[&amp;#34;path&amp;#34;] = new_name
    return self.__class__(**new_obj)
```
5. The lack of validation allows copying any file the Gradio process can read&lt;/p&gt;
&lt;p&gt;### PoC
The following script demonstrates the vulnerability by…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: gradio&lt;/p&gt;
&lt;p&gt;An arbitrary file copy vulnerability in Gradio&amp;#39;s flagging feature allows unauthenticated attackers to copy any readable file from the server&amp;#39;s filesystem. While attackers can&amp;#39;t read these copied files, they can cause DoS by copying large files (like /dev/urandom) to fill disk space.&lt;/p&gt;
&lt;p&gt;### Description
The flagging component doesn&amp;#39;t properly validate file paths before copying files. Attackers can send specially crafted requests to the `/gradio_api/run/predict` endpoint to trigger these file copies.&lt;/p&gt;
&lt;p&gt;**Source**: User-controlled `path` parameter in the flagging functionality JSON payload  
**Sink**: `shutil.copy` operation in `FileData._copy_to_dir()` method&lt;/p&gt;
&lt;p&gt;The vulnerable code flow:
1. A JSON payload is sent to the `/gradio_api/run/predict` endpoint
2. The `path` field within `FileData` object can reference any file on the system
3. When processing this request, the `Component.flag()` method creates a `GradioDataModel` object
4. The `FileData._copy_to_dir()` method uses this path without proper validation:&lt;/p&gt;
&lt;p&gt;```python
def _copy_to_dir(self, dir: str) -&amp;gt; FileData:
    pathlib.Path(dir).mkdir(exist_ok=True)
    new_obj = dict(self)&lt;/p&gt;
&lt;p&gt;if not self.path:
        raise ValueError(&amp;#34;Source file path is not set&amp;#34;)
    new_name = shutil.copy(self.path, dir)  # vulnerable sink
    new_obj[&amp;#34;path&amp;#34;] = new_name
    return self.__class__(**new_obj)
```
5. The lack of validation allows copying any file the Gradio process can read&lt;/p&gt;
&lt;p&gt;### PoC
The following script demonstrates the vulnerability by…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-8jw3-6x8j-v96g</guid>
    </item>
  </channel>
</rss>
