PT-2023-28006 · Gradio · Gradio

Published

2023-09-15

·

Updated

2023-09-19

·

CVE-2023-41626

CVSS v3.1

4.8

Medium

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Gradio version 3.27.0
Description The issue is related to an arbitrary file upload vulnerability. This vulnerability can be exploited via the "/upload" interface.
Recommendations For Gradio version 3.27.0, consider disabling the /upload interface until a patch is available to prevent exploitation of the arbitrary file upload vulnerability.

Fix

Unrestricted File Upload

Weakness Enumeration

Related Identifiers

CVE-2023-41626
GHSA-V4Q9-QGQF-7JWP

Affected Products

Gradio