Launch Week Day 1: Announcing Security Design Review
CRITICAL 9.8 PyPI

Withdrawn Advisory: Gradio was discovered to contain a code injection vulnerability via the component /gradio/component_meta.py

GHSA-9v2f-6vcg-3hgv · CVE-2024-39236 · PYSEC-2024-274

Published · Modified

Description

Withdrawn Advisory

This advisory has been withdrawn because the it only affects a user who runs specifically crafted code that happens to use gradio library. More information can be found here.

Original Description

Gradio v4.36.1 was discovered to contain a code injection vulnerability via the component /gradio/component_meta.py. This vulnerability is triggered via a crafted input.

Ready to move

Start Securing

Free, no credit card | First findings in minutes