Arbitrary File Copy Vulnerability in Gradio Python Package
CVE-2025-48889

5.3MEDIUM

Key Information:

Vendor

Gradio-app

Status
Vendor
CVE Published:
30 May 2025

What is CVE-2025-48889?

Gradio, an open-source Python package for building machine learning demos and applications, was found to have a vulnerability in its flagging feature prior to version 5.31.0. This flaw allows unauthenticated attackers to copy any readable file from the server's filesystem, posing a risk of potential Denial of Service (DoS) when large files are copied, thus consuming disk space. Although attackers cannot access the contents of the copied files, the risk of server disruption is significant. Users are encouraged to upgrade to version 5.31.0 or later to mitigate this vulnerability.

Affected Version(s)

gradio < 5.31.0

References

CVSS V3.1

Score:
5.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-48889 : Arbitrary File Copy Vulnerability in Gradio Python Package