Home » Database

AVID-2026-R1304

Description

Make the /file secure against file traversal attacks (CVE-2023-51449)

Details

Gradio is an open-source Python package that allows you to quickly build a demo or web application for your machine learning model, API, or any arbitary Python function. Versions of gradio prior to 4.11.0 contained a vulnerability in the /file route which made them susceptible to file traversal attacks in which an attacker could access arbitrary files on a machine running a Gradio app with a public URL (e.g. if the demo was created with share=True, or on Hugging Face Spaces) if they knew the path of files to look for. This issue has been patched in version 4.11.0.

Reason for inclusion in AVID: CVE-2023-51449 concerns Gradio, a Python package used to build ML demos/apps. The vulnerability in the /file route allows file traversal to access arbitrary files on a Gradio app with a public URL, affecting software dependencies/frameworks used in AI pipelines. This is a software supply-chain issue (library/component used to build AI systems) and constitutes a security vulnerability (CWE-22). The report includes affected versions, patch information, and references (NVD, GitHub advisories) providing sufficient signal. Therefore, it should be kept for AVID curation.

References

Affected or Relevant Artifacts

  • Developer: gradio-app
  • Deployer: gradio-app
  • Artifact Details:
TypeName
Systemgradio

Impact

AVID Taxonomy Categorization

  • Risk domains: Security
  • SEP subcategories: S0100: Software Vulnerability
  • Lifecycle stages: L06: Deployment

CVSS

Version3.1
Vector StringCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L
Base Score5.6
Base Severity🟠 Medium
Attack VectorNETWORK
Attack Complexity🔴 High
Privileges RequiredNONE
User InteractionNONE
ScopeUNCHANGED
Confidentiality Impact🟢 Low
Integrity Impact🟢 Low
Availability Impact🟢 Low

CWE

IDDescription
CWE-22CWE-22: Improper Limitation of a Pathname to a Restricted Directory (‘Path Traversal’)

Other information

  • Report Type: Advisory
  • Credits:
  • Date Reported: 2023-12-22
  • Version: 0.3.3
  • AVID Entry