PT-2025-12120 · Gradio+1 · Gradio+1

Published

2025-03-20

·

Updated

2025-10-21

·

CVE-2024-12065

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions haotian-liu/llava at commit c121f04
Description A local file inclusion issue exists, allowing an attacker to access any file on the system by sending multiple crafted requests to the server. This is due to improper input validation in the gradio web UI component.
Recommendations For haotian-liu/llava at commit c121f04, consider disabling the gradio web UI component until a patch is available to prevent exploitation. Restrict access to sensitive files and directories to minimize the risk of unauthorized access. At the moment, there is no information about a newer version that contains a fix for this issue.

Exploit

Fix

Path traversal

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2024-12065

Affected Products

Gradio
Llava