Intel

AIKIDO-2025-10009

gradio is vulnerable to Unrestricted File Upload

Unrestricted File Upload Pre-CVE
Found by Aikido Intel before public disclosure or CVE publication.

55

Medium Risk

This Affects:

pythongradio
4.19.1 - 5.9.1
Fixed in 5.10.0

TL;DR

Affected versions of this package are affected by unrestricted file uploads due to insecure methods that improperly handle file extensions and MIME types when processing files. This vulnerability could allow an attacker to upload malicious files, such as malware, leading to critical security issues and misbehavior.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

gradio is vulnerable to Unrestricted File Upload in versions 4.19.1 - 5.9.1.

How to fix this

Upgrade the gradio library to the patch version.