Vulnerability PYSEC-2026-1418

Medium Risk
MEDIUM RISK
CVSS Score: 5.3
Score Range: 4.0–6.9
Medium severity vulnerabilities (CVSS 4.0–6.9). Important issues that meaningfully reduce security confidence.
2 months ago
July 07, 2026 at 02:34 PM UTC
Gradio Path Traversal vulnerability
0.1.0 - 5.0.1
0.1.0 - 5.0.1

Summary

Gradio Path Traversal vulnerability

Details

A vulnerability in the gradio-app/gradio repository, version git 67e4044, allows for path traversal on Windows OS. The implementation of the blocked_path functionality, which is intended to disallow users from reading certain files, is flawed. Specifically, while the application correctly blocks access to paths like 'C:/tmp/secret.txt', it fails to block access when using NTFS Alternate Data Streams (ADS) syntax, such as 'C:/tmp/secret.txt::$DATA'. This flaw can lead to unauthorized reading of blocked file paths.

Impacted packages

Timeline

Published
2 months ago
July 07, 2026 at 02:34 PM UTC
Last Modified
2 months ago
July 07, 2026 at 05:47 PM UTC