SOURCE-LINKED INTELLIGENCE
GHSA-48cq-79qq-6f7x: Gradio applications running locally vulnerable to 3rd party websites accessing routes and uploading files
### Impact This CVE covers the ability of 3rd party websites to access routes and upload files to users running Gradio applications locally. For example, the malicious owners of [www.dontvisitme.com](http://www.dontvisitme.com/) could put a script on their website that uploads a large file to http://localhost:7860/upload and anyone who visits their website and has a Gradio app will now have that large file uploaded on their computer ### Patches Yes, the problem has been patched in Gradio version 4.19.2 or higher. We have no knowledge of this exploit being used against users of Gradio applicati
Read original source ↗ Open in workspace
- recordType
- vulnerability
- status
- active
- evidenceStatus
- reported
- region
- Global
Evidence & attribution
- OSV AI package advisories · 2024-05-21T14:43:50.000Z
- OSV AI package advisories · 2026-07-07T11:45:43.162Z
First collected: 2026-09-19T20:28:21.856Z. This is not the publication date.