gradio is vulnerable to Server-side Request Forgery (SSRF)
65
Medium Risk
A server-side request forgery (SSRF) vulnerability exists in Gradio where user-controlled URLs are fetched during SVG image processing and audio output handling without adequate validation. The affected code performs server-side HTTP requests and returns the fetched content to clients, allowing an attacker to induce requests to internal services, cloud metadata endpoints, or other non-public resources and potentially exfiltrate sensitive information. Users should upgrade to a fixed version that enforces URL validation, redirect re-validation, and protections against access to internal network addresses.
You are affected if you are using a version that falls within the vulnerable range.
gradio is vulnerable to Server-side Request Forgery (SSRF) in versions 5.0.0 - 6.15.2.
Upgrade the gradio library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant