Information disclosure in Gradio - CVE-2023-25823
Published: February 23, 2023 / Updated: April 28, 2026
Gradio
Gradio
Description
The vulnerability allows a remote attacker to access other users' shared Gradio demos.
The vulnerability exists due to exposure of a private SSH key in share links in Gradio when handling connections to the Gradio machine. A remote attacker can connect to the Gradio machine to access other users' shared Gradio demos.
Only applications using share links with share=True are affected.