SOURCE-LINKED INTELLIGENCE
GHSA-g9cj-cfpp-4g2x: gradio vulnerable to Path Traversal
An issue was discovered in gradio-app/gradio, where the `/component_server` endpoint improperly allows the invocation of any method on a `Component` class with attacker-controlled arguments. Specifically, by exploiting the `move_resource_to_block_cache()` method of the `Block` class, an attacker can copy any file on the filesystem to a temporary directory and subsequently retrieve it. This vulnerability enables unauthorized local file read access, posing a significant risk especially when the application is exposed to the internet via `launch(share=True)`, thereby allowing remote attackers to
Read original source ↗ Open in workspace
- recordType
- vulnerability
- status
- active
- evidenceStatus
- reported
- region
- Global
Evidence & attribution
- OSV AI package advisories · 2024-04-16T00:30:33.000Z
- OSV AI package advisories · 2026-07-07T11:45:39.252Z
First collected: 2026-09-19T20:28:21.856Z. This is not the publication date.