References https://nvd.nist.gov/vuln/detail/CVE-2024-4325 https://github.com/advisories/GHSA-973g-55hp-3frw https://security.snyk.io/vuln/SNYK-PYTHON-GRADIO-7217838 https://huntr.com/bounties/b34f084b-7d14-4f00-bc10-048a3a5aaf88 https://avd.aliyun.com/detail?id=AVD-2024-4325 https://cve.imfht.com/detail/CVE-2024-4325 https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2024/CVE-2024-4325.yaml https://advisories.checkpoint.com/defense/advisories/public/2026/cpai-2024-5254.html https://db.gcve.eu/vuln/cve-2024-4325
Related VulnerabilitiesGradio /proxy 服务器端请求伪造漏洞(CVE-2023-34239)PoCCVE-2026-28414: Gradio - Absolute Path TraversalGradio /static//windows/win.ini 文件读取漏洞 (CVE-2026-28414)PoCgradio-file-redirect: Gradio - Open RedirectPoCgradio-image-ssrf: Gradio Image Component - Server-Side Request ForgeryPoCgradio-lfi: Gradio - Local File Inclusiongradio /queue/join 服务器端请求伪造漏洞(CVE-2024-4325)gradio /file 服务器端请求伪造漏洞(CVE-2024-1183)PoCCVE-2021-43831: Gradio < 2.5.0 - Arbitrary File ReadPoCCVE-2023-51449: Gradio Hugging Face - Local File InclusionPoCCVE-2024-1183: Gradio - Server Side Request Forgery