PT-2025-12126 · Gradio · Gradio

Published

2024-11-10

·

Updated

2025-03-20

·

CVE-2024-12217

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions gradio-app/gradio version git 67e4044
Description A flaw in the implementation of the blocked path functionality allows for path traversal on Windows OS. The application fails to block access when using NTFS Alternate Data Streams (ADS) syntax, such as 'C:/tmp/secret.txt::$DATA', which can lead to unauthorized reading of blocked file paths.
Recommendations For version git 67e4044, consider disabling the blocked path functionality until a patch is available to prevent path traversal attacks. Restrict access to sensitive files and directories to minimize the risk of exploitation. Avoid using NTFS Alternate Data Streams (ADS) syntax in file paths to prevent bypassing the blocked path functionality.

Exploit

Fix

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-01839
CVE-2024-12217
GHSA-PRPG-P95C-32FV

Affected Products

Gradio