CVE Feed

    Dashboard / CVE / CVE-2021-43831

    CVE-2021-43831

    Gradio is an open source framework for building interactive machine learning models and demos. In versions prior to 2.5.0 there is a vulnerability that affects anyone who creates and publicly shares Gradio interfaces. File paths are not restricted and users who receive a Gradio link can access any files on the host computer if they know the file names or file paths. This is limited only by the host operating system. Paths are opened in read only mode. The problem has been patched in gradio 2.5.0.

    Published:Dec 15, 2021
    Last Modified:Nov 21, 2024
    EPS:Dec 15, 2021
    EPSS Score:0.30342
    CVSS Score:7.7

    Affected Products

    Vendor
    Gradio Project
    Product
    Gradio

    Related CVEs

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High