Vulnerability PYSEC-2026-1418
Medium Risk
MEDIUM RISK
CVSS Score: 5.3
Score Range: 4.0–6.9
Medium severity vulnerabilities (CVSS 4.0–6.9). Important issues that meaningfully reduce security confidence.
2 months ago
July 07, 2026 at 02:34 PM UTC
Gradio Path Traversal vulnerability
0.1.0 - 5.0.1
0.1.0 - 5.0.1
Summary
Gradio Path Traversal vulnerability
Details
A vulnerability in the gradio-app/gradio repository, version git 67e4044, allows for path traversal on Windows OS. The implementation of the blocked_path functionality, which is intended to disallow users from reading certain files, is flawed. Specifically, while the application correctly blocks access to paths like 'C:/tmp/secret.txt', it fails to block access when using NTFS Alternate Data Streams (ADS) syntax, such as 'C:/tmp/secret.txt::$DATA'. This flaw can lead to unauthorized reading of blocked file paths.
Related Vulnerabilities
Other vulnerabilities affecting the same packages
Low Risk
2 months ago
Gradio CORS Origin Validation Bypass Vulnerability
5.0.0 - 5.29.1 PYSEC-2026-1423
5.0.0 - 5.29.1 PYSEC-2026-1423
High Risk
2 months ago
Gradio DOS in multipart boundry while uploading the file
0.1.0 - 5.22.0 PYSEC-2026-1410
0.1.0 - 5.22.0 PYSEC-2026-1410
Medium Risk
2 months ago
Gradio Vulnerable to Open Redirect
0.1.0 - 4.37.2 PYSEC-2026-1411
0.1.0 - 4.37.2 PYSEC-2026-1411
High Risk
2 months ago
Gradio Vulnerable to Denial of Service (DoS) via Crafted Zip Bomb
4.0.0 - 5.0.0b1 PYSEC-2026-1412
4.0.0 - 5.0.0b1 PYSEC-2026-1412
High Risk
2 months ago
Gradio Vulnerable to Arbitrary File Deletion
4.0.0 - 5.0.0b1 PYSEC-2026-1417
4.0.0 - 5.0.0b1 PYSEC-2026-1417
Impacted packages
Timeline
Published
2 months ago
July 07, 2026 at 02:34 PM UTC
Last Modified
2 months ago
July 07, 2026 at 05:47 PM UTC