Download of code without integrity check in Gradio - CVE-2024-47867

 

Download of code without integrity check in Gradio - CVE-2024-47867

Published: October 10, 2024 / Updated: April 28, 2026


Vulnerability identifier: #VU128280
CSH Severity: Medium
CVSS v4: 8.3 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2024-47867
CWE-ID: CWE-494
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to introduce malicious code.

The vulnerability exists due to improper integrity verification in the FRP client download mechanism when downloading the FRP client from a remote URL. A remote attacker can modify the downloaded binary to introduce malicious code.

Exploitation requires access to the remote URL from which the FRP client is downloaded.


Affected software

Gradio

How to mitigate CVE-2024-47867

Install security update from vendor's website.

Gradio - update to 5.0.0

External References

Related Security Bulletins