Arbitrary File Copy Vulnerability in Gradio Python Package
CVE-2025-48889
5.3MEDIUM
What is CVE-2025-48889?
Gradio, an open-source Python package for building machine learning demos and applications, was found to have a vulnerability in its flagging feature prior to version 5.31.0. This flaw allows unauthenticated attackers to copy any readable file from the server's filesystem, posing a risk of potential Denial of Service (DoS) when large files are copied, thus consuming disk space. Although attackers cannot access the contents of the copied files, the risk of server disruption is significant. Users are encouraged to upgrade to version 5.31.0 or later to mitigate this vulnerability.
Affected Version(s)
gradio < 5.31.0