Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-rj25-5m4j-hcxq

Опубликовано: 08 июл. 2026
Источник: github
Github: Не прошло ревью
CVSS4: 4.9
CVSS3: 7.4

Описание

Gradio before 6.20.0 contains an open redirect and server-side request forgery vulnerability that allows attackers to redirect users to arbitrary URLs or perform client-side SSRF by supplying unvalidated HTTP/HTTPS URLs to the file_fetch() function in the /gradio_api/file= endpoint. Attackers can craft a malicious FileData response targeting internal endpoints such as cloud metadata services to retrieve sensitive credentials including EC2 IAM role credentials.

Gradio before 6.20.0 contains an open redirect and server-side request forgery vulnerability that allows attackers to redirect users to arbitrary URLs or perform client-side SSRF by supplying unvalidated HTTP/HTTPS URLs to the file_fetch() function in the /gradio_api/file= endpoint. Attackers can craft a malicious FileData response targeting internal endpoints such as cloud metadata services to retrieve sensitive credentials including EC2 IAM role credentials.

EPSS

Процентиль: 36%
0.00437
Низкий

4.9 Medium

CVSS4

7.4 High

CVSS3

Дефекты

CWE-601

Связанные уязвимости

CVSS3: 7.4
nvd
около 2 месяцев назад

Gradio before 6.20.0 contains an open redirect and server-side request forgery vulnerability that allows attackers to redirect users to arbitrary URLs or perform client-side SSRF by supplying unvalidated HTTP/HTTPS URLs to the file_fetch() function in the /gradio_api/file= endpoint. Attackers can craft a malicious FileData response targeting internal endpoints such as cloud metadata services to retrieve sensitive credentials including EC2 IAM role credentials.

EPSS

Процентиль: 36%
0.00437
Низкий

4.9 Medium

CVSS4

7.4 High

CVSS3

Дефекты

CWE-601