{"schema_version":1,"title":"gradio (PyPI) vulnerabilities","summary":"Junglewise Threat Intelligence has tracked 54 vulnerabilities in gradio (PyPI): 0 in the last 7 days and 20 in the last 90 days, 2 of them critical and 0 exploited in the wild. The most recent, CVE-2026-59806, was published on 8 July 2026.","url":"https://junglewise.ai/threats/technologies/gradio","json_url":"https://junglewise.ai/threats/technologies/gradio.json","publisher":"Junglewise Threat Intelligence","license":"CC-BY-4.0","license_url":"https://creativecommons.org/licenses/by/4.0/","attribution":"Junglewise Threat Intelligence, https://junglewise.ai/threats/technologies/gradio","sources":"NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories","kind":"technology","counts":{"high":5,"all_time":54,"critical":2,"exploited":0,"last_7_days":0,"last_30_days":0,"last_90_days":20,"last_365_days":26},"latest":[{"cve":"CVE-2026-59806","cvss":7.4,"slug":"cve-2026-59806-gradio-open-redirect-and-ssrf-in-file-fetch-function","title":"Gradio open redirect and SSRF in file_fetch function","severity":"high","exploited":false,"published_at":"2026-07-08T20:16:56.973+00:00","url":"https://junglewise.ai/threats/cve-2026-59806-gradio-open-redirect-and-ssrf-in-file-fetch-function"},{"cve":"CVE-2025-5320","cvss":3.1,"epss":0.0026,"slug":"cve-2025-5320-gradio-cors-origin-validation-bypass-vulnerability","title":"PYSEC-2026-1423 - Gradio CORS Origin Validation Bypass Vulnerability","severity":"low","exploited":false,"published_at":"2026-07-07T16:02:53.404531+00:00","url":"https://junglewise.ai/threats/cve-2025-5320-gradio-cors-origin-validation-bypass-vulnerability"},{"cve":"CVE-2024-8966","cvss":3,"epss":0.0079,"slug":"cve-2024-8966-gradio-dos-in-multipart-boundry-while-uploading-the-file","title":"PYSEC-2026-1410 - Gradio DOS in multipart boundry while uploading the file","severity":"low","exploited":false,"published_at":"2026-07-07T14:34:57.483886+00:00","url":"https://junglewise.ai/threats/cve-2024-8966-gradio-dos-in-multipart-boundry-while-uploading-the-file"},{"cve":"CVE-2024-8021","cvss":3,"epss":0.0074,"slug":"cve-2024-8021-gradio-vulnerable-to-open-redirect","title":"PYSEC-2026-1411 - Gradio Vulnerable to Open Redirect","severity":"low","exploited":false,"published_at":"2026-07-07T14:34:56.196943+00:00","url":"https://junglewise.ai/threats/cve-2024-8021-gradio-vulnerable-to-open-redirect"},{"cve":"CVE-2024-12217","cvss":3,"epss":0.0069,"slug":"cve-2024-12217-gradio-path-traversal-vulnerability","title":"PYSEC-2026-1418 - Gradio Path Traversal vulnerability","severity":"low","exploited":false,"published_at":"2026-07-07T14:34:52.925368+00:00","url":"https://junglewise.ai/threats/cve-2024-12217-gradio-path-traversal-vulnerability"},{"cve":"CVE-2024-10648","cvss":3,"epss":0.0072,"slug":"cve-2024-10648-gradio-vulnerable-to-arbitrary-file-deletion","title":"PYSEC-2026-1417 - Gradio Vulnerable to Arbitrary File Deletion","severity":"low","exploited":false,"published_at":"2026-07-07T14:34:51.739857+00:00","url":"https://junglewise.ai/threats/cve-2024-10648-gradio-vulnerable-to-arbitrary-file-deletion"},{"cve":"CVE-2024-10569","cvss":3,"epss":0.0065,"slug":"cve-2024-10569-gradio-vulnerable-to-denial-of-service-dos-via-crafted-zip-bomb","title":"PYSEC-2026-1412 - Gradio Vulnerable to Denial of Service (DoS) via Crafted Zip Bomb","severity":"low","exploited":false,"published_at":"2026-07-07T14:34:51.623084+00:00","url":"https://junglewise.ai/threats/cve-2024-10569-gradio-vulnerable-to-denial-of-service-dos-via-crafted-zip-bomb"},{"cve":"CVE-2024-10624","cvss":3,"epss":0.0108,"slug":"cve-2024-10624-gradio-vulnerable-to-denial-of-service-dos-via-crafted-http","title":"PYSEC-2026-1421 - Gradio Vulnerable to Denial of Service (DoS) via Crafted HTTP Request","severity":"low","exploited":false,"published_at":"2026-07-07T14:34:51.478734+00:00","url":"https://junglewise.ai/threats/cve-2024-10624-gradio-vulnerable-to-denial-of-service-dos-via-crafted-http"},{"cve":"CVE-2024-48052","cvss":3.1,"epss":0.0047,"slug":"cve-2024-48052-gradio-downloadbutton-server-side-request-forgery","title":"PYSEC-2026-1408 - gradio Server Side Request Forgery vulnerability","severity":"low","exploited":false,"published_at":"2026-07-07T14:34:43.855277+00:00","url":"https://junglewise.ai/threats/cve-2024-48052-gradio-downloadbutton-server-side-request-forgery"},{"cve":"CVE-2024-4940","cvss":3,"epss":0.0102,"slug":"cve-2024-4940-open-redirect-in-gradio","title":"PYSEC-2026-1414 - Open redirect in gradio","severity":"low","exploited":false,"published_at":"2026-07-07T14:34:35.206769+00:00","url":"https://junglewise.ai/threats/cve-2024-4940-open-redirect-in-gradio"},{"cve":"CVE-2024-4325","cvss":3,"epss":0.3737,"slug":"cve-2024-4325-server-side-request-forgery-in-gradio","title":"PYSEC-2026-1413 - Server-Side Request Forgery in gradio","severity":"low","exploited":false,"published_at":"2026-07-07T11:45:45.793189+00:00","url":"https://junglewise.ai/threats/cve-2024-4325-server-side-request-forgery-in-gradio"},{"cve":"CVE-2024-1727","cvss":3.1,"epss":0.0035,"slug":"cve-2024-1727-gradio-applications-running-locally-vulnerable-to-3rd-party","title":"PYSEC-2026-1409 - Gradio applications running locally vulnerable to 3rd party websites accessing routes and uploading files","severity":"low","exploited":false,"published_at":"2026-07-07T11:45:43.162093+00:00","url":"https://junglewise.ai/threats/cve-2024-1727-gradio-applications-running-locally-vulnerable-to-3rd-party"},{"cve":"CVE-2024-34511","cvss":3.1,"slug":"cve-2024-34511-gradio-component-server-improper-server-function-validation","title":"PYSEC-2026-1407 - Gradio's Component Server does not properly consider` _is_server_fn` for functions","severity":"low","exploited":false,"published_at":"2026-07-07T11:45:41.724874+00:00","url":"https://junglewise.ai/threats/cve-2024-34511-gradio-component-server-improper-server-function-validation"},{"cve":"CVE-2024-1561","cvss":3,"epss":0.0931,"slug":"cve-2024-1561-gradio-vulnerable-to-path-traversal","title":"PYSEC-2026-1415 - gradio vulnerable to Path Traversal","severity":"low","exploited":false,"published_at":"2026-07-07T11:45:39.252079+00:00","url":"https://junglewise.ai/threats/cve-2024-1561-gradio-vulnerable-to-path-traversal"},{"cve":"CVE-2024-1183","cvss":3,"epss":0.018,"slug":"cve-2024-1183-gradio-server-side-request-forgery-vulnerability","title":"PYSEC-2026-1419 - gradio Server-Side Request Forgery vulnerability","severity":"low","exploited":false,"published_at":"2026-07-07T11:45:38.870824+00:00","url":"https://junglewise.ai/threats/cve-2024-1183-gradio-server-side-request-forgery-vulnerability"},{"cve":"CVE-2024-2206","cvss":3,"epss":0.0042,"slug":"cve-2024-2206-gradio-server-side-request-forgery-vulnerability","title":"PYSEC-2026-1420 - gradio Server-Side Request Forgery vulnerability","severity":"low","exploited":false,"published_at":"2026-07-07T11:45:36.786545+00:00","url":"https://junglewise.ai/threats/cve-2024-2206-gradio-server-side-request-forgery-vulnerability"},{"cve":"CVE-2024-1729","cvss":3,"epss":0.005,"slug":"cve-2024-1729-gradio-apps-vulnerable-to-timing-attacks-to-guess-password","title":"PYSEC-2026-1416 - Gradio apps vulnerable to timing attacks to guess password","severity":"low","exploited":false,"published_at":"2026-07-07T11:45:32.827149+00:00","url":"https://junglewise.ai/threats/cve-2024-1729-gradio-apps-vulnerable-to-timing-attacks-to-guess-password"},{"cve":"CVE-2023-41626","cvss":3.1,"epss":0.0041,"slug":"cve-2023-41626-gradio-arbitrary-file-upload-vulnerability","title":"PYSEC-2026-1422 - Gradio arbitrary file upload vulnerability","severity":"low","exploited":false,"published_at":"2026-07-07T11:45:24.600625+00:00","url":"https://junglewise.ai/threats/cve-2023-41626-gradio-arbitrary-file-upload-vulnerability"},{"cve":"CVE-2026-49119","cvss":7.5,"epss":0.0093,"slug":"cve-2026-49119-gradio-path-traversal-in-fileexplorer-component","title":"Gradio path traversal in FileExplorer component","severity":"high","exploited":false,"published_at":"2026-07-01T19:16:52.463+00:00","url":"https://junglewise.ai/threats/cve-2026-49119-gradio-path-traversal-in-fileexplorer-component"},{"cve":"CVE-2024-1728","cvss":3.1,"epss":0.8539,"slug":"cve-2024-1728-gradio-allows-users-to-access-arbitrary-files","title":"PYSEC-2026-345 - Gradio allows users to access arbitrary files","severity":"low","exploited":false,"published_at":"2026-06-29T11:50:40.923365+00:00","url":"https://junglewise.ai/threats/cve-2024-1728-gradio-allows-users-to-access-arbitrary-files"},{"cve":"CVE-2026-10783","cvss":3.1,"epss":0.0011,"slug":"cve-2026-10783-gradio-weak-hash-in-save-audio-to-cache-audio-caching","title":"Gradio weak hash in save_audio_to_cache audio caching","severity":"low","exploited":false,"published_at":"2026-06-04T00:16:59.01+00:00","url":"https://junglewise.ai/threats/cve-2026-10783-gradio-weak-hash-in-save-audio-to-cache-audio-caching"},{"cve":"CVE-2026-48545","cvss":6.8,"epss":0.0047,"slug":"cve-2026-48545-gradio-session-fixation-via-shared-proxy-cookie-jar","title":"Gradio session fixation via shared proxy cookie jar","severity":"medium","exploited":false,"published_at":"2026-05-27T15:16:31.02+00:00","url":"https://junglewise.ai/threats/cve-2026-48545-gradio-session-fixation-via-shared-proxy-cookie-jar"},{"cve":"CVE-2026-28416","cvss":8.2,"epss":0.0034,"slug":"cve-2026-28416-gradio-ssrf-via-malicious-proxy-url-in-gr-load","title":"Gradio SSRF via malicious proxy_url in gr.load","severity":"high","exploited":false,"published_at":"2026-03-01T01:29:31+00:00","url":"https://junglewise.ai/threats/cve-2026-28416-gradio-ssrf-via-malicious-proxy-url-in-gr-load"},{"cve":"CVE-2026-28415","cvss":4.3,"epss":0.0028,"slug":"cve-2026-28415-gradio-open-redirect-in-oauth-flow","title":"Gradio open redirect in OAuth flow","severity":"medium","exploited":false,"published_at":"2026-03-01T01:29:12+00:00","url":"https://junglewise.ai/threats/cve-2026-28415-gradio-open-redirect-in-oauth-flow"},{"cve":"CVE-2026-28414","cvss":7.5,"epss":0.0249,"slug":"cve-2026-28414-gradio-absolute-path-traversal-on-windows-with-python-3-13","title":"Gradio absolute path traversal on Windows with Python 3.13+","severity":"high","exploited":false,"published_at":"2026-03-01T01:28:41+00:00","url":"https://junglewise.ai/threats/cve-2026-28414-gradio-absolute-path-traversal-on-windows-with-python-3-13"}],"weekly":[{"week":"2026-06-29","critical":0,"exploited":0,"vulnerabilities":2},{"week":"2026-07-06","critical":0,"exploited":0,"vulnerabilities":18},{"week":"2026-07-13","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-20","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-27","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-03","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-10","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-17","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-24","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-31","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-07","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-14","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-21","critical":0,"exploited":0,"vulnerabilities":0}],"related":[{"name":"tensorflow (PyPI)","slug":"pypi-tensorflow","vulnerabilities":428,"url":"https://junglewise.ai/threats/technologies/pypi-tensorflow"},{"name":"tensorflow-cpu (PyPI)","slug":"tensorflow-cpu","vulnerabilities":424,"url":"https://junglewise.ai/threats/technologies/tensorflow-cpu"},{"name":"tensorflow-gpu (PyPI)","slug":"tensorflow-gpu","vulnerabilities":421,"url":"https://junglewise.ai/threats/technologies/tensorflow-gpu"},{"name":"open-webui (PyPI)","slug":"open-webui","vulnerabilities":177,"url":"https://junglewise.ai/threats/technologies/open-webui"},{"name":"Django (PyPI)","slug":"django","vulnerabilities":172,"url":"https://junglewise.ai/threats/technologies/django"},{"name":"apache-airflow (PyPI)","slug":"apache-airflow","vulnerabilities":152,"url":"https://junglewise.ai/threats/technologies/apache-airflow"},{"name":"plone (PyPI)","slug":"pypi-plone","vulnerabilities":101,"url":"https://junglewise.ai/threats/technologies/pypi-plone"},{"name":"praisonai (PyPI)","slug":"pypi-praisonai","vulnerabilities":86,"url":"https://junglewise.ai/threats/technologies/pypi-praisonai"},{"name":"exiv2 (PyPI)","slug":"exiv2","vulnerabilities":85,"url":"https://junglewise.ai/threats/technologies/exiv2"},{"name":"nltk (PyPI)","slug":"nltk","vulnerabilities":83,"url":"https://junglewise.ai/threats/technologies/nltk"},{"name":"mlflow (PyPI)","slug":"mlflow","vulnerabilities":82,"url":"https://junglewise.ai/threats/technologies/mlflow"},{"name":"pillow (PyPI)","slug":"pillow","vulnerabilities":79,"url":"https://junglewise.ai/threats/technologies/pillow"}],"technology":{"hub":true,"name":"gradio (PyPI)","slug":"gradio","vendor":{"name":"PyPI","slug":"pypi","url":"https://junglewise.ai/threats/vendors/pypi"},"aliases":[],"homepage":"https://gradio.app","repo_url":"https://github.com/gradio-app/gradio","description":"A Python library for building web interfaces for machine learning models.","url":"https://junglewise.ai/threats/technologies/gradio"},"most_severe":[{"cve":"CVE-2024-39236","cvss":9.8,"epss":0.0087,"slug":"cve-2024-39236-gradio-code-injection-in-component-meta-py","title":"Gradio code injection in component_meta.py","severity":"critical","exploited":false,"published_at":"2024-07-01T21:31:15+00:00","url":"https://junglewise.ai/threats/cve-2024-39236-gradio-code-injection-in-component-meta-py"},{"cve":"CVE-2025-23042","cvss":4,"epss":0.0098,"slug":"cve-2025-23042-gradio-acl-bypass-via-case-insensitive-path-manipulation","title":"Gradio ACL bypass via case-insensitive path manipulation","severity":"critical","exploited":false,"published_at":"2025-01-14T16:32:22+00:00","url":"https://junglewise.ai/threats/cve-2025-23042-gradio-acl-bypass-via-case-insensitive-path-manipulation"},{"cve":"CVE-2026-28416","cvss":8.2,"epss":0.0034,"slug":"cve-2026-28416-gradio-ssrf-via-malicious-proxy-url-in-gr-load","title":"Gradio SSRF via malicious proxy_url in gr.load","severity":"high","exploited":false,"published_at":"2026-03-01T01:29:31+00:00","url":"https://junglewise.ai/threats/cve-2026-28416-gradio-ssrf-via-malicious-proxy-url-in-gr-load"},{"cve":"CVE-2026-28414","cvss":7.5,"epss":0.0249,"slug":"cve-2026-28414-gradio-absolute-path-traversal-on-windows-with-python-3-13","title":"Gradio absolute path traversal on Windows with Python 3.13+","severity":"high","exploited":false,"published_at":"2026-03-01T01:28:41+00:00","url":"https://junglewise.ai/threats/cve-2026-28414-gradio-absolute-path-traversal-on-windows-with-python-3-13"},{"cve":"CVE-2024-0964","cvss":7.5,"epss":0.0096,"slug":"cve-2024-0964-gradio-path-traversal-in-api-request-handling","title":"Gradio path traversal in API request handling","severity":"high","exploited":false,"published_at":"2024-02-06T00:30:28+00:00","url":"https://junglewise.ai/threats/cve-2024-0964-gradio-path-traversal-in-api-request-handling"},{"cve":"CVE-2026-49119","cvss":7.5,"epss":0.0093,"slug":"cve-2026-49119-gradio-path-traversal-in-fileexplorer-component","title":"Gradio path traversal in FileExplorer component","severity":"high","exploited":false,"published_at":"2026-07-01T19:16:52.463+00:00","url":"https://junglewise.ai/threats/cve-2026-49119-gradio-path-traversal-in-fileexplorer-component"},{"cve":"CVE-2026-59806","cvss":7.4,"slug":"cve-2026-59806-gradio-open-redirect-and-ssrf-in-file-fetch-function","title":"Gradio open redirect and SSRF in file_fetch function","severity":"high","exploited":false,"published_at":"2026-07-08T20:16:56.973+00:00","url":"https://junglewise.ai/threats/cve-2026-59806-gradio-open-redirect-and-ssrf-in-file-fetch-function"},{"cve":"CVE-2026-48545","cvss":6.8,"epss":0.0047,"slug":"cve-2026-48545-gradio-session-fixation-via-shared-proxy-cookie-jar","title":"Gradio session fixation via shared proxy cookie jar","severity":"medium","exploited":false,"published_at":"2026-05-27T15:16:31.02+00:00","url":"https://junglewise.ai/threats/cve-2026-48545-gradio-session-fixation-via-shared-proxy-cookie-jar"},{"cve":"CVE-2025-48889","cvss":5.3,"epss":0.0066,"slug":"cve-2025-48889-gradio-unauthorized-file-copy-via-path-manipulation-in-flagging","title":"Gradio unauthorized file copy via path manipulation in flagging feature","severity":"medium","exploited":false,"published_at":"2025-05-29T22:36:59+00:00","url":"https://junglewise.ai/threats/cve-2025-48889-gradio-unauthorized-file-copy-via-path-manipulation-in-flagging"},{"cve":"CVE-2026-28415","cvss":4.3,"epss":0.0028,"slug":"cve-2026-28415-gradio-open-redirect-in-oauth-flow","title":"Gradio open redirect in OAuth flow","severity":"medium","exploited":false,"published_at":"2026-03-01T01:29:12+00:00","url":"https://junglewise.ai/threats/cve-2026-28415-gradio-open-redirect-in-oauth-flow"}],"generated_at":"2026-09-27T03:07:00.185062+00:00"}