Path Traversal Vulnerability in Gradio Application by Gradio Team
CVE-2024-12217

5.3MEDIUM

Key Information:

Vendor

Gradio-app

Vendor
CVE Published:
20 March 2025

What is CVE-2024-12217?

A flaw in the Gradio application allows attackers to bypass file access restrictions on Windows systems. While the application is designed to limit access to specific paths via its blocked_path feature, it fails to adequately handle NTFS Alternate Data Streams (ADS) syntax. This oversight can permit unauthorized reading of sensitive files that the application is supposed to protect, enhancing the risk of data exposure and privacy breaches. Users should take note of this vulnerability to safeguard their file systems against unauthorized access.

Affected Version(s)

gradio-app/gradio <= unspecified

References

CVSS V3.0

Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.