CVE-2024-1727

A Cross-Site Request Forgery (CSRF) vulnerability in gradio-app/gradio allows attackers to upload multiple large files to a victim's system if they are running Gradio locally. By crafting a malicious HTML page that triggers an unauthorized file upload to the victim's server, an attacker can deplete the system's disk space, potentially leading to a denial of service. This issue affects the file upload functionality as implemented in gradio/routes.py.
CVSS

No CVSS.

Configurations

Configuration 1 (hide)

cpe:2.3:a:gradio_project:gradio:*:*:*:*:*:python:*:*

History

30 Jul 2025, 20:11

Type Values Removed Values Added
CWE CWE-352
CPE cpe:2.3:a:gradio_project:gradio:*:*:*:*:*:python:*:*
References () https://huntr.com/bounties/a94d55fb-0770-4cbe-9b20-97a978a2ffff - () https://huntr.com/bounties/a94d55fb-0770-4cbe-9b20-97a978a2ffff - Exploit, Third Party Advisory
References () https://github.com/gradio-app/gradio/commit/84802ee6a4806c25287344dce581f9548a99834a - () https://github.com/gradio-app/gradio/commit/84802ee6a4806c25287344dce581f9548a99834a - Patch
First Time Gradio Project
Gradio Project gradio

16 Apr 2024, 12:15

Type Values Removed Values Added
Summary To prevent malicious 3rd party websites from making requests to Gradio applications running locally, this PR tightens the CORS rules around Gradio applications. In particular, it checks to see if the host header is localhost (or one of its aliases) and if so, it requires the origin header (if present) to be localhost (or one of its aliases) as well. A Cross-Site Request Forgery (CSRF) vulnerability in gradio-app/gradio allows attackers to upload multiple large files to a victim's system if they are running Gradio locally. By crafting a malicious HTML page that triggers an unauthorized file upload to the victim's server, an attacker can deplete the system's disk space, potentially leading to a denial of service. This issue affects the file upload functionality as implemented in gradio/routes.py.

21 Mar 2024, 20:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-03-21 20:15

Updated : 2025-07-30 20:11


NVD link : CVE-2024-1727

Mitre link : CVE-2024-1727


JSON object : View

Products Affected

gradio_project

  • gradio
CWE

No CWE.