Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-pgfv-gvc5-prfg

Опубликовано: 20 мар. 2025
Источник: github
Github: Прошло ревью
CVSS3: 8.2

Описание

Gradio Vulnerable to Arbitrary File Deletion

A path traversal vulnerability exists in the Gradio Audio component of gradio-app/gradio, as of version git 98cbcae. This vulnerability allows an attacker to control the format of the audio file, leading to arbitrary file content deletion. By manipulating the output format, an attacker can reset any file to an empty file, causing a denial of service (DOS) on the server.

Пакеты

Наименование

gradio

pip
Затронутые версииВерсия исправления

>= 4.0.0, <= 5.0.0b2

Отсутствует

EPSS

Процентиль: 48%
0.00245
Низкий

8.2 High

CVSS3

Дефекты

CWE-29

Связанные уязвимости

CVSS3: 8.2
nvd
11 месяцев назад

A path traversal vulnerability exists in the Gradio Audio component of gradio-app/gradio, as of version git 98cbcae. This vulnerability allows an attacker to control the format of the audio file, leading to arbitrary file content deletion. By manipulating the output format, an attacker can reset any file to an empty file, causing a denial of service (DOS) on the server.

EPSS

Процентиль: 48%
0.00245
Низкий

8.2 High

CVSS3

Дефекты

CWE-29