PT-2024-18255 · Gradio · Gradio

CVE-2024-1727

·

Published

2024-03-21

·

Updated

2026-07-07

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L
Name of the Vulnerable Software and Affected Versions gradio versions prior to 4.19.2
Description A Cross-Site Request Forgery (CSRF) issue allows attackers to upload multiple large files to a victim's system if they are running Gradio locally. By crafting a malicious HTML page that triggers an unauthorized file upload to the victim's server, an attacker can deplete the system's disk space, potentially leading to a denial of service. This issue affects the file upload functionality as implemented in gradio/routes.py. The problem can be exploited by malicious third-party websites making requests to Gradio applications running locally.
Recommendations For gradio versions prior to 4.19.2, update to Gradio version 4.19.2 or higher to resolve the issue. As a temporary workaround, consider restricting access to the file upload functionality until the update is applied.

Exploit

Fix

DoS

CSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2024-1727
GHSA-3X9G-XFJ5-FQ84
GHSA-48CQ-79QQ-6F7X
PYSEC-2026-1409

Affected Products

Gradio