CVE-2024-1561 is a critical local file read vulnerability affecting gradio-app/gradio versions 4.3 through 4.12. It allows an unauthenticated attacker to read arbitrary files from the host system by exploiting the /component_server endpoint, particularly when applications are exposed via launch(share=True) or hosted on huggingface.co. Rated with a CVSS score of 7.5 (HIGH), this vulnerability has a low attack complexity and no user interaction required, enabling remote attackers to achieve high confidentiality impact by accessing sensitive data like API keys and credentials. While not currently listed in CISA's KEV catalog, a Nuclei template for this vulnerability exists, indicating readily available exploit code. Despite its high EPSS score and FAUCET Risk Score, there is currently no public social media discussion or media coverage surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 4.12.0, < 4.13.0CPE matchmatch criteria | cpe:2.3:a:gradio_project:gradio:*:*:*:*:*:python:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.