Executive brief
Gradio is an open-source Python library used to build web interfaces for machine learning models. A security flaw in its audio caching system allows different audio files with identical raw data but different settings (like sample rate or format) to be stored in the same location. This could potentially allow a local user to access or overwrite cached audio data belonging to other sessions, leading to minor data exposure or incorrect file delivery.
Technical details
A vulnerability in the `save_audio_to_cache` function of Gradio's Audio Cache Key Handler results in the use of a weak hash for cache directory naming. The implementation derives the cache key solely from raw audio bytes (`data.tobytes()`), ignoring critical metadata such as sample rate, format, dtype, and shape. Consequently, two different audio outputs with identical raw sample bytes but different interpretation metadata resolve to the same cache namespace. An attacker with local access could exploit this collision to cause the application to serve incorrect cached audio files or potentially access data from a different context. The issue is addressed in version 6.15.1 by including metadata in the cache key generation.
Affected products
- gradio-app gradio < 6.15.1
Timeline
- 2026-05-16: disclosed: Issue reported on GitHub
- 2026-05-26: patched: Fix merged into main branch
- 2026-06-04: advisory: GitHub Advisory and CVE published