Junglewise Threat Intelligence

CVE-2024-39236: Gradio code injection in component_meta.py

CVE-2024-39236 · Severity: critical · CVSS 9.8 · Published 2024-07-01

Technologies: Gradio. Vendors: PyPI.

Executive brief

Gradio, a popular Python library for building machine learning web interfaces, was reported to have a code injection vulnerability. If exploited, an attacker could potentially execute arbitrary code on the server hosting the Gradio application. However, the advisory was later withdrawn because the issue only occurs when a developer runs specifically crafted, untrusted code that uses the library, rather than being a vulnerability in the library's standard operation.

Technical details

A code injection vulnerability (CWE-94) was identified in Gradio v4.36.1 within the 'gradio/component_meta.py' component. The flaw allegedly allowed for arbitrary code execution via crafted input. Following further review, the advisory was withdrawn by the maintainers because the vulnerability is only reachable if a user executes specifically malicious code that utilizes the Gradio library, rather than being an exploitable flaw in the library's handling of external user input in a standard deployment. The original CVSS score was 9.8, reflecting the potential for unauthenticated remote code execution.

Affected products

  • Gradio Gradio 4.36.1

Timeline

  • 2024-07-01: disclosed
  • 2024-07-01: advisory: Original GHSA published
  • 2025-10-17: other: Advisory withdrawn by GitHub/Maintainers

References

Related threats