Gradio

Vendor:

First CVE: Dec 15, 2021 · Active for 4 years

50
Total CVEs
More Total CVEs than 98% of tracked products
8.3
Avg CVEs / Year
Higher CVE frequency than 95% of tracked products
7.1
Avg CVSS
Higher Avg CVSS than 46% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Gradio over time

Volume of CVEsAvg CVSS Base Score
First CVE
Dec 15, 2021
4 years ago
Most Recent CVE
Jul 1, 2026
27 days ago

CVE Severity & Scoring

Gradio50 CVEs
All CVEs353,240 CVEs
LowMediumHighCritical
Attack Vector
Local1 (2.0%)
Network49 (98.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low43 (86.0%)
High7 (14.0%)
Unknown0 (0.0%)
User Interaction
None39 (78.0%)
Unknown0 (0.0%)
Required11 (22.0%)
Privileges Required
Low7 (14.0%)
High0 (0.0%)
None43 (86.0%)
Unknown0 (0.0%)

Top CVEs

Signals from CVEs in this product scope (50 CVEs).

50 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
gradio-app/gradio is vulnerable to a local file inclusion vulnerability due to improper validation of user-supplied input in the UploadButton component. Attackers can exploit this
Apr 10, 20247.577NOYES
A Server-Side Request Forgery (SSRF) vulnerability exists in the gradio-app/gradio version 4.21.0, specifically within the `/queue/join` endpoint and the `save_url_to_cache` functi
Jun 6, 20248.656NOYES
Gradio is an open-source Python package that allows you to quickly build a demo or web application for your machine learning model, API, or any arbitary Python function. Versions o
Dec 22, 20237.547NOYES
Gradio is an open-source Python package designed for quick prototyping. Prior to version 6.7, Gradio apps running on Window with Python 3.13+ are vulnerable to an absolute path tra
Feb 27, 20267.538NOYES
An issue was discovered in gradio-app/gradio, where the `/component_server` endpoint improperly allows the invocation of any method on a `Component` class with attacker-controlled
Apr 16, 20247.538NOYES
Gradio is an open source framework for building interactive machine learning models and demos. In versions prior to 2.5.0 there is a vulnerability that affects anyone who creates a
Dec 15, 20217.736NOYES
Gradio before 6.16.0 contain a path traversal vulnerability in the FileExplorer component's preprocess() method that allows unauthenticated attackers to escape the configured root
Jul 1, 20267.535NONO
Gradio is an open-source Python package designed for quick prototyping. Prior to version 6.6.0, a Server-Side Request Forgery (SSRF) vulnerability in Gradio allows an attacker to m
Feb 27, 20268.633NONO
Gradio is an open-source Python library to build machine learning and data science demos and web applications. Versions prior to 3.13.1 contain Use of Hard-coded Credentials. When
Feb 23, 20239.829NONO
`gradio` is an open source framework for building interactive machine learning models and demos. Prior to version 2.8.11, `gradio` suffers from Improper Neutralization of Formula E
Mar 17, 20228.829NONO

Exploit Exposure

Signals from CVEs in this product scope (50 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
9 CVEs
18.0% of CVEs· 98th percentile
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

Signals from CVEs in this product scope (50 CVEs).

Media Mentions

Signals from CVEs in this product scope (50 CVEs).

Top CNAs Publishing CVEs For Gradio

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
6.14.012.50.1%00
4.36.119.80.9%00
4.36.016.11.0%01
3.27.014.80.4%00
2024-09-1837.70.8%00
0.39.117.50.7%00