PT-2025-12126 · Gradio · Gradio
Published
2024-11-10
·
Updated
2025-03-20
·
CVE-2024-12217
CVSS v3.1
5.3
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
gradio-app/gradio version git 67e4044
Description
A flaw in the implementation of the blocked path functionality allows for path traversal on Windows OS. The application fails to block access when using NTFS Alternate Data Streams (ADS) syntax, such as 'C:/tmp/secret.txt::$DATA', which can lead to unauthorized reading of blocked file paths.
Recommendations
For version git 67e4044, consider disabling the blocked path functionality until a patch is available to prevent path traversal attacks. Restrict access to sensitive files and directories to minimize the risk of exploitation. Avoid using NTFS Alternate Data Streams (ADS) syntax in file paths to prevent bypassing the blocked path functionality.
Exploit
Fix
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Gradio