Loading HuntDB...

GHSA-g6c9-f4xm-9j4x

GitHub Security Advisory

Open redirect in gradio

✓ GitHub Reviewed MODERATE Has CVE

Advisory Details

An open redirect vulnerability exists in the gradio-app/gradio, affecting the latest version. The vulnerability allows an attacker to redirect users to arbitrary websites, which can be exploited for phishing attacks, Cross-site Scripting (XSS), Server-Side Request Forgery (SSRF), amongst others. This issue is due to improper validation of user-supplied input in the handling of URLs. Attackers can exploit this vulnerability by crafting a malicious URL that, when processed by the application, redirects the user to an attacker-controlled web page.

Affected Packages

PyPI gradio
Affected versions: 0 (last affected: 4.36.1)

Related CVEs

Key Information

GHSA ID
GHSA-g6c9-f4xm-9j4x
Published
June 22, 2024 6:30 AM
Last Modified
June 24, 2024 9:14 PM
CVSS Score
5.0 /10
Primary Ecosystem
PyPI
Primary Package
gradio
GitHub Reviewed
✓ Yes

Dataset

Last updated: September 11, 2025 6:35 AM

Data from GitHub Advisory Database. This information is provided for research and educational purposes.