Files on the host computer can be accessed from the Gradio interface
Critical severity
GitHub Reviewed
Published
Dec 15, 2021
in
gradio-app/gradio
•
Updated Nov 18, 2024
Description
Published by the National Vulnerability Database
Dec 15, 2021
Reviewed
Jan 18, 2022
Published to the GitHub Advisory Database
Jan 21, 2022
Last updated
Nov 18, 2024
Impact
This is a vulnerability that affects anyone who creates and publicly shares Gradio interfaces using
gradio<2.4.8
. Because of the way that static files were being served, someone who generated a public Gradio link and shared it with others would potentially be exposing the files on the computer that generated the link, while the link was active. An attacker would be able to view the contents of a file on the computer if they knew the exact relative filepath. We do not have any evidence that this was ever exploited, but we treated the issue seriously and immediately took steps to mitigate it (see below)Response
gradio 2.5.0
, within 24 hours of the issue being brought to our attentiongradio
Patches
The problem has been patched in
gradio>=2.5.0
.References