SB2023022366 - Information disclosure in Gradio
Published: February 23, 2023 Updated: April 28, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 vulnerability.
1) Information disclosure (CVE-ID: CVE-2023-25823)
The vulnerability allows a remote attacker to access other users' shared Gradio demos.
The vulnerability exists due to exposure of a private SSH key in share links in Gradio when handling connections to the Gradio machine. A remote attacker can connect to the Gradio machine to access other users' shared Gradio demos.
Only applications using share links with share=True are affected.
Remediation
Install update from vendor's website.