GHSA-3gf9-wv65-gwh9
GitHub Security Advisory
gradio Server Side Request Forgery vulnerability
✓ GitHub Reviewed
MODERATE
Has CVE
Advisory Details
In gradio <=4.42.0, the gr.DownloadButton function has a hidden server-side request forgery (SSRF) vulnerability. The reason is that within the save_url_to_cache function, there are no restrictions on the URL, which allows access to local target resources. This can lead to the download of local resources and sensitive information.
Affected Packages
PyPI
gradio
Affected versions:
0
(last affected: 4.42.0)
Related CVEs
Key Information
5.0
/10
Dataset
Last updated: July 13, 2025 6:28 AM
Data from GitHub Advisory Database. This information is provided for research and educational purposes.