Junglewise Threat Intelligence

CVE-2025-23042: Gradio ACL bypass via case-insensitive path manipulation

CVE-2025-23042 · Severity: critical · CVSS 4 · Published 2025-01-14

Technologies: gradio (PyPI). Vendors: PyPI.

Executive brief

Gradio, a popular library for building machine learning web interfaces, contains a security flaw that allows unauthorized access to restricted files. When hosted on Windows or macOS, an attacker can bypass file access restrictions by simply changing the capitalization of the requested file path. This could lead to the exposure of sensitive data, such as configuration files, user information, or API keys, potentially compromising the entire application.

Technical details

A vulnerability exists in Gradio's path validation logic within the `is_allowed_file` function. The implementation fails to perform case normalization when comparing requested file paths against the `blocked_paths` list. On case-insensitive operating systems like Windows and macOS, an attacker can bypass the ACL by requesting a blocked file using different casing (e.g., 'adMin' instead of 'admin'). This allows remote, unauthenticated attackers to access sensitive files on the local file system that were intended to be restricted. The issue is fixed in version 5.11.0 by implementing proper path normalization.

Affected products

  • gradio-app gradio < 5.11.0

Timeline

  • 2025-01-14: disclosed
  • 2025-01-14: advisory
  • 2025-01-14: patched: Fixed in version 5.11.0

References

Related threats