SOURCE-LINKED INTELLIGENCE
GHSA-qh6x-j82h-vpf9: gradio Server-Side Request Forgery vulnerability
An SSRF (Server-Side Request Forgery) vulnerability exists in the gradio-app/gradio repository, allowing attackers to scan and identify open ports within an internal network. By manipulating the 'file' parameter in a GET request, an attacker can discern the status of internal ports based on the presence of a 'Location' header or a 'File not allowed' error in the response.
Read original source ↗ Open in workspace
- recordType
- vulnerability
- status
- active
- evidenceStatus
- reported
- region
- Global
Evidence & attribution
- OSV AI package advisories · 2024-04-16T00:30:32.000Z
- OSV AI package advisories · 2026-07-07T11:45:38.870Z
First collected: 2026-09-19T20:28:21.856Z. This is not the publication date.