Vulnerability PYSEC-2026-1417
High Risk
HIGH RISK
CVSS Score: 8.2
Score Range: 7.0–8.9
High severity vulnerabilities (CVSS 7.0–8.9). Serious vulnerabilities that should be prioritized soon after critical fixes.
2 months ago
July 07, 2026 at 02:34 PM UTC
Gradio Vulnerable to Arbitrary File Deletion
4.0.0 - 5.0.0b1
4.0.0 - 5.0.0b1
Summary
Gradio Vulnerable to Arbitrary File Deletion
Details
A path traversal vulnerability exists in the Gradio Audio component of gradio-app/gradio, as of version git 98cbcae. This vulnerability allows an attacker to control the format of the audio file, leading to arbitrary file content deletion. By manipulating the output format, an attacker can reset any file to an empty file, causing a denial of service (DOS) on the server.
Related Vulnerabilities
Other vulnerabilities affecting the same packages
Low Risk
2 months ago
Gradio CORS Origin Validation Bypass Vulnerability
5.0.0 - 5.29.1 PYSEC-2026-1423
5.0.0 - 5.29.1 PYSEC-2026-1423
High Risk
2 months ago
Gradio DOS in multipart boundry while uploading the file
0.1.0 - 5.22.0 PYSEC-2026-1410
0.1.0 - 5.22.0 PYSEC-2026-1410
Medium Risk
2 months ago
Gradio Vulnerable to Open Redirect
0.1.0 - 4.37.2 PYSEC-2026-1411
0.1.0 - 4.37.2 PYSEC-2026-1411
Medium Risk
2 months ago
Gradio Path Traversal vulnerability
0.1.0 - 5.0.1 PYSEC-2026-1418
0.1.0 - 5.0.1 PYSEC-2026-1418
High Risk
2 months ago
Gradio Vulnerable to Denial of Service (DoS) via Crafted Zip Bomb
4.0.0 - 5.0.0b1 PYSEC-2026-1412
4.0.0 - 5.0.0b1 PYSEC-2026-1412
Impacted packages
Timeline
Published
2 months ago
July 07, 2026 at 02:34 PM UTC
Last Modified
2 months ago
July 07, 2026 at 05:47 PM UTC