Path Traversal Vulnerability in Gradio Application by Gradio Team
CVE-2024-12217
5.3MEDIUM
What is CVE-2024-12217?
A flaw in the Gradio application allows attackers to bypass file access restrictions on Windows systems. While the application is designed to limit access to specific paths via its blocked_path feature, it fails to adequately handle NTFS Alternate Data Streams (ADS) syntax. This oversight can permit unauthorized reading of sensitive files that the application is supposed to protect, enhancing the risk of data exposure and privacy breaches. Users should take note of this vulnerability to safeguard their file systems against unauthorized access.
Affected Version(s)
gradio-app/gradio <= unspecified