Improper access control in Gradio - CVE-2024-1727
Published: May 21, 2024 / Updated: April 28, 2026
Gradio
Gradio
Description
The vulnerability allows a remote attacker to upload files to a user's computer.
The vulnerability exists due to improper access control in the upload route when handling cross-origin requests from a third-party website. A remote attacker can host a malicious website that submits a crafted request to the local Gradio application to upload files to a user's computer.
The issue affects users running Gradio applications locally while visiting a third-party website.