Описание
Gradio Path Traversal vulnerability
A local file include could be remotely triggered in Gradio due to a vulnerable user-supplied JSON value in an API request.
Пакеты
Наименование
gradio
pip
Затронутые версииВерсия исправления
< 4.9.0
4.9.0
Связанные уязвимости
CVSS3: 9.4
nvd
около 2 лет назад
A local file include could be remotely triggered in Gradio due to a vulnerable user-supplied JSON value in an API request.