AIIC AI Intelligence Centre

SOURCE-LINKED INTELLIGENCE

GHSA-3gf9-wv65-gwh9: gradio Server Side Request Forgery vulnerability

OSV AI package advisories · observation · Nov 5, 2024 · UTC

In gradio <=4.42.0, the gr.DownloadButton function has a hidden server-side request forgery (SSRF) vulnerability. The reason is that within the save_url_to_cache function, there are no restrictions on the URL, which allows access to local target resources. This can lead to the download of local resources and sensitive information.

Read original source ↗ Open in workspace

recordType
vulnerability
status
active
evidenceStatus
reported
region
Global

Evidence & attribution

First collected: 2026-09-19T20:28:21.856Z. This is not the publication date.