Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-59806

Опубликовано: 08 июл. 2026
Источник: nvd
CVSS3: 7.4
EPSS Низкий

Описание

Gradio before 6.20.0 contains an open redirect and server-side request forgery vulnerability that allows attackers to redirect users to arbitrary URLs or perform client-side SSRF by supplying unvalidated HTTP/HTTPS URLs to the file_fetch() function in the /gradio_api/file= endpoint. Attackers can craft a malicious FileData response targeting internal endpoints such as cloud metadata services to retrieve sensitive credentials including EC2 IAM role credentials.

EPSS

Процентиль: 36%
0.00437
Низкий

7.4 High

CVSS3

Дефекты

CWE-601

Связанные уязвимости

CVSS3: 7.4
github
около 2 месяцев назад

Gradio before 6.20.0 contains an open redirect and server-side request forgery vulnerability that allows attackers to redirect users to arbitrary URLs or perform client-side SSRF by supplying unvalidated HTTP/HTTPS URLs to the file_fetch() function in the /gradio_api/file= endpoint. Attackers can craft a malicious FileData response targeting internal endpoints such as cloud metadata services to retrieve sensitive credentials including EC2 IAM role credentials.

EPSS

Процентиль: 36%
0.00437
Низкий

7.4 High

CVSS3

Дефекты

CWE-601