Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Gradio Project

First CVE: Dec 15, 2021Active for: 5 yearsTotal CVEs: 51
58.9
VTI Score
TOP TARGET

Gradio Project maintains a focused open-source framework for building machine-learning web interfaces, with vulnerabilities concentrated in the core Gradio library and associated video-handling components. Vulnerabilities affecting this vendor skew toward serious outcomes, with an elevated share reaching critical severity and a frequent tendency toward public exploit availability, reflecting the exposure inherent to web-facing applications that handle user input and file operations. The exposure recurs through weakness classes including path traversal, server-side request forgery, open redirect, and improper authorization that are characteristic of web frameworks processing untrusted input and managing access controls across HTTP interfaces. Defenders should treat Gradio deployments—particularly those exposed to untrusted networks or handling sensitive data—as requiring prompt patching when advisories are released, given the combination of serious severity and public exploit tooling. Current exploitation activity and exposure counts are shown alongside this summary.

FAUCET AI Generated
51
Total CVEs
More Total CVEs than 98% of tracked vendors
4.3
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 99% of tracked vendors
7.1
Avg CVSS Score
Higher Avg CVSS Score than 52% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Gradio Project over time

Volume of CVEsAvg CVSS Base Score
First CVE
Dec 15, 2021
4 years ago
Most Recent CVE
Jul 1, 2026
23 days ago

Products(1 total)

Top CVEs

Signals from CVEs in this vendor scope (51 CVEs).

51 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2024-1728HIGH
gradio-app/gradio is vulnerable to a local file inclusion vulnerability due to improper validation of user-supplied input in the UploadButton component. Attackers can exploit this
Apr 10, 20247.577NOYES
CVE-2024-4325HIGH
A Server-Side Request Forgery (SSRF) vulnerability exists in the gradio-app/gradio version 4.21.0, specifically within the `/queue/join` endpoint and the `save_url_to_cache` functi
Jun 6, 20248.656NOYES
CVE-2026-28414HIGH
Gradio is an open-source Python package designed for quick prototyping. Prior to version 6.7, Gradio apps running on Window with Python 3.13+ are vulnerable to an absolute path tra
Feb 27, 20267.538NOYES
CVE-2024-1561HIGH
An issue was discovered in gradio-app/gradio, where the `/component_server` endpoint improperly allows the invocation of any method on a `Component` class with attacker-controlled
Apr 16, 20247.538NOYES
CVE-2021-43831HIGH
Gradio is an open source framework for building interactive machine learning models and demos. In versions prior to 2.5.0 there is a vulnerability that affects anyone who creates a
Dec 15, 20217.736NOYES
CVE-2026-49119HIGH
Gradio before 6.16.0 contain a path traversal vulnerability in the FileExplorer component's preprocess() method that allows unauthenticated attackers to escape the configured root
Jul 1, 20267.535NONO
CVE-2023-51449HIGH
Gradio is an open-source Python package that allows you to quickly build a demo or web application for your machine learning model, API, or any arbitary Python function. Versions o
Dec 22, 20237.533NOYES
CVE-2026-28416HIGH
Gradio is an open-source Python package designed for quick prototyping. Prior to version 6.6.0, a Server-Side Request Forgery (SSRF) vulnerability in Gradio allows an attacker to m
Feb 27, 20268.630NONO
CVE-2023-25823CRITICAL
Gradio is an open-source Python library to build machine learning and data science demos and web applications. Versions prior to 3.13.1 contain Use of Hard-coded Credentials. When
Feb 23, 20239.829NONO
CVE-2022-24770HIGH
`gradio` is an open source framework for building interactive machine learning models and demos. Prior to version 2.8.11, `gradio` suffers from Improper Neutralization of Formula E
Mar 17, 20228.829NONO
View all 51 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products51 CVEs
33%
49%
14%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local1 (2.0%)
Network50 (98.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low44 (86.3%)
High7 (13.7%)
Unknown0 (0.0%)
User Interaction
None40 (78.4%)
Unknown0 (0.0%)
Required11 (21.6%)
Privileges Required
Low7 (13.7%)
High0 (0.0%)
None44 (86.3%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (51 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
9 CVEs
17.6% of CVEs· 97th percentile
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Gradio Project.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Gradio Project — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Gradio Project's Products

View all 5 CNAs →

Top CWEs