PT-2024-30005 · Gradio · Gradio

Published

2024-06-04

·

Updated

2025-10-15

·

CVE-2024-4254

CVSS v3.1

7.1

High

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:L/A:N
Name of the Vulnerable Software and Affected Versions gradio-app/gradio (affected versions not specified)
Description The 'deploy-website.yml' workflow in the gradio-app/gradio repository is vulnerable to secrets exfiltration due to improper authorization. This vulnerability arises from the workflow's explicit checkout and execution of code from a fork, allowing the running of untrusted code in an environment with access to push to the base repository and access secrets. Sensitive secrets such as GITHUB TOKEN, HF TOKEN, VERCEL ORG ID, VERCEL PROJECT ID, COMMENT TOKEN, AWSACCESSKEYID, AWSSECRETKEY, and VERCEL TOKEN could be exfiltrated.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Improper Authorization

Weakness Enumeration

Related Identifiers

CVE-2024-4254

Affected Products

Gradio