Gradio
Vendor:
First CVE: Dec 15, 2021 · Active for 4 years
50
Total CVEs
More Total CVEs than 98% of tracked products
8.3
Avg CVEs / Year
Higher CVE frequency than 95% of tracked products
7.1
Avg CVSS
Higher Avg CVSS than 46% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Gradio over time
Volume of CVEsAvg CVSS Base Score
First CVE
Dec 15, 2021
4 years ago
Most Recent CVE
Jul 1, 2026
27 days ago
CVE Severity & Scoring
Gradio50 CVEs
34%
48%
14%
All CVEs353,240 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local1 (2.0%)
Network49 (98.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low43 (86.0%)
High7 (14.0%)
Unknown0 (0.0%)
User Interaction
None39 (78.0%)
Unknown0 (0.0%)
Required11 (22.0%)
Privileges Required
Low7 (14.0%)
High0 (0.0%)
None43 (86.0%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (50 CVEs).
50 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-1728HIGH gradio-app/gradio is vulnerable to a local file inclusion vulnerability due to improper validation of user-supplied input in the UploadButton component. Attackers can exploit this | Apr 10, 2024 | 7.5 | 77 | NO | YES |
CVE-2024-4325HIGH A Server-Side Request Forgery (SSRF) vulnerability exists in the gradio-app/gradio version 4.21.0, specifically within the `/queue/join` endpoint and the `save_url_to_cache` functi | Jun 6, 2024 | 8.6 | 56 | NO | YES |
CVE-2023-51449HIGH Gradio is an open-source Python package that allows you to quickly build a demo or web application for your machine learning model, API, or any arbitary Python function. Versions o | Dec 22, 2023 | 7.5 | 47 | NO | YES |
CVE-2026-28414HIGH Gradio is an open-source Python package designed for quick prototyping. Prior to version 6.7, Gradio apps running on Window with Python 3.13+ are vulnerable to an absolute path tra | Feb 27, 2026 | 7.5 | 38 | NO | YES |
CVE-2024-1561HIGH An issue was discovered in gradio-app/gradio, where the `/component_server` endpoint improperly allows the invocation of any method on a `Component` class with attacker-controlled | Apr 16, 2024 | 7.5 | 38 | NO | YES |
CVE-2021-43831HIGH Gradio is an open source framework for building interactive machine learning models and demos. In versions prior to 2.5.0 there is a vulnerability that affects anyone who creates a | Dec 15, 2021 | 7.7 | 36 | NO | YES |
CVE-2026-49119HIGH Gradio before 6.16.0 contain a path traversal vulnerability in the FileExplorer component's preprocess() method that allows unauthenticated attackers to escape the configured root | Jul 1, 2026 | 7.5 | 35 | NO | NO |
CVE-2026-28416HIGH Gradio is an open-source Python package designed for quick prototyping. Prior to version 6.6.0, a Server-Side Request Forgery (SSRF) vulnerability in Gradio allows an attacker to m | Feb 27, 2026 | 8.6 | 33 | NO | NO |
CVE-2023-25823CRITICAL Gradio is an open-source Python library to build machine learning and data science demos and web applications. Versions prior to 3.13.1 contain Use of Hard-coded Credentials. When | Feb 23, 2023 | 9.8 | 29 | NO | NO |
CVE-2022-24770HIGH `gradio` is an open source framework for building interactive machine learning models and demos. Prior to version 2.8.11, `gradio` suffers from Improper Neutralization of Formula E | Mar 17, 2022 | 8.8 | 29 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (50 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
9 CVEs
18.0% of CVEs· 98th percentile
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (50 CVEs).
Media Mentions
Signals from CVEs in this product scope (50 CVEs).
Top CNAs Publishing CVEs For Gradio
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 6.14.0 | 1 | 2.5 | 0.1% | 0 | 0 |
| 4.36.1 | 1 | 9.8 | 0.9% | 0 | 0 |
| 4.36.0 | 1 | 6.1 | 1.0% | 0 | 1 |
| 3.27.0 | 1 | 4.8 | 0.4% | 0 | 0 |
| 2024-09-18 | 3 | 7.7 | 0.8% | 0 | 0 |
| 0.39.1 | 1 | 7.5 | 0.7% | 0 | 0 |