Gradio Project maintains a focused open-source framework for building machine-learning web interfaces, with vulnerabilities concentrated in the core Gradio library and associated video-handling components. Vulnerabilities affecting this vendor skew toward serious outcomes, with an elevated share reaching critical severity and a frequent tendency toward public exploit availability, reflecting the exposure inherent to web-facing applications that handle user input and file operations. The exposure recurs through weakness classes including path traversal, server-side request forgery, open redirect, and improper authorization that are characteristic of web frameworks processing untrusted input and managing access controls across HTTP interfaces. Defenders should treat Gradio deployments—particularly those exposed to untrusted networks or handling sensitive data—as requiring prompt patching when advisories are released, given the combination of serious severity and public exploit tooling. Current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Gradio Project over time
Signals from CVEs in this vendor scope (51 CVEs).
51 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-1728HIGH gradio-app/gradio is vulnerable to a local file inclusion vulnerability due to improper validation of user-supplied input in the UploadButton component. Attackers can exploit this | Apr 10, 2024 | 7.5 | 77 | NO | YES |
CVE-2024-4325HIGH A Server-Side Request Forgery (SSRF) vulnerability exists in the gradio-app/gradio version 4.21.0, specifically within the `/queue/join` endpoint and the `save_url_to_cache` functi | Jun 6, 2024 | 8.6 | 56 | NO | YES |
CVE-2026-28414HIGH Gradio is an open-source Python package designed for quick prototyping. Prior to version 6.7, Gradio apps running on Window with Python 3.13+ are vulnerable to an absolute path tra | Feb 27, 2026 | 7.5 | 38 | NO | YES |
CVE-2024-1561HIGH An issue was discovered in gradio-app/gradio, where the `/component_server` endpoint improperly allows the invocation of any method on a `Component` class with attacker-controlled | Apr 16, 2024 | 7.5 | 38 | NO | YES |
CVE-2021-43831HIGH Gradio is an open source framework for building interactive machine learning models and demos. In versions prior to 2.5.0 there is a vulnerability that affects anyone who creates a | Dec 15, 2021 | 7.7 | 36 | NO | YES |
CVE-2026-49119HIGH Gradio before 6.16.0 contain a path traversal vulnerability in the FileExplorer component's preprocess() method that allows unauthenticated attackers to escape the configured root | Jul 1, 2026 | 7.5 | 35 | NO | NO |
CVE-2023-51449HIGH Gradio is an open-source Python package that allows you to quickly build a demo or web application for your machine learning model, API, or any arbitary Python function. Versions o | Dec 22, 2023 | 7.5 | 33 | NO | YES |
CVE-2026-28416HIGH Gradio is an open-source Python package designed for quick prototyping. Prior to version 6.6.0, a Server-Side Request Forgery (SSRF) vulnerability in Gradio allows an attacker to m | Feb 27, 2026 | 8.6 | 30 | NO | NO |
CVE-2023-25823CRITICAL Gradio is an open-source Python library to build machine learning and data science demos and web applications. Versions prior to 3.13.1 contain Use of Hard-coded Credentials. When | Feb 23, 2023 | 9.8 | 29 | NO | NO |
CVE-2022-24770HIGH `gradio` is an open source framework for building interactive machine learning models and demos. Prior to version 2.8.11, `gradio` suffers from Improper Neutralization of Formula E | Mar 17, 2022 | 8.8 | 29 | NO | NO |
Signals from CVEs in this vendor scope (51 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Gradio Project.
Media articles that mention a CVE ID that affects a product developed by Gradio Project — matched by CVE ID, not by vendor name.