Executive brief
Gradio, a popular library for building machine learning web interfaces, contains a vulnerability in its data flagging feature. An unauthenticated attacker can remotely trigger the server to copy any file it has access to into a public directory. This can be used to exhaust server disk space, potentially leading to a complete service outage.
Technical details
An arbitrary file copy vulnerability exists in Gradio's flagging component due to insufficient validation of the 'path' parameter within the FileData object. By sending a specially crafted JSON payload to the '/gradio_api/run/predict' endpoint, an unauthenticated attacker can control the source path passed to the 'shutil.copy' operation in the 'FileData._copy_to_dir()' method. While the attacker cannot directly read the contents of the copied files through this specific bug, they can target large system files (e.g., /dev/urandom) to fill the server's disk space, causing a Denial of Service (DoS). The vulnerability is addressed in Gradio version 5.31.0.
Affected products
- gradio-app gradio < 5.31.0
Timeline
- 2025-05-29: disclosed
- 2025-05-29: advisory
- 2025-05-29: patched: Fixed in version 5.31.0