Vulnerabilidades em gradio-app
50 resultadosAnálise Vexday
A Gradio registra 50 vulnerabilidades no histórico, com apenas 1 crítica e nenhuma sob ataque ativo no momento, reduzindo a urgência imediata. A fraqueza dominante é path traversal (CWE-22), padrão em aplicações web, e 4 novos registros nos últimos 90 dias indicam descobertas contínuas, mas em ritmo moderado. O risco está contido enquanto não houver exploração ativa, exigindo vigilância rotineira sobre patches.
CVE-2024-47168LOWThe `enable_monitoring` flag set to `False` does not disable monitoring in GradioEPSS 0.3%CVE-2024-47869LOWNon-constant-time comparison when comparing hashes in GradioEPSS 0.3%CVE-2024-47165MEDIUMCORS origin validation accepts the null origin in GradioEPSS 0.3%CVE-2024-47872MEDIUMCross-site Scripting on Gradio server via upload of HTML files, JS files, or SVG filesEPSS 0.3%CVE-2026-59806MEDIUMGradio < 6.20.0 - Open Redirect and SSRF via /gradio_api/file= endpointEPSS 0.2%CVE-2025-5320MEDIUMgradio-app gradio CORS is_valid_origin privilege escalationEPSS 0.2%CVE-2026-28415MEDIUMGradio has Open Redirect in OAuth FlowEPSS 0.2%CVE-2024-47867LOWLack of integrity check on the downloaded FRP client in GradioEPSS 0.2%CVE-2024-47871HIGHInsecure communication between the FRP client and server in GradioEPSS 0.2%CVE-2026-10783LOWgradio-app gradio Audio Cache Key save_audio_to_cache weak hashEPSS 0.1%