/Vulnerability Library

Gradio - Absolute Path Traversal

CVE-2026-28414
Verified

Description

Gradio < 6.7 on Windows with Python 3.13+ contains an absolute path traversal caused by incorrect path validation in path joining logic, letting unauthenticated attackers read arbitrary files from the server.

Severity

High

CVSS Score

7.5

Exploit Probability

2%

Affected Product

gradio

Published Date

March 31, 2026

Template Author

0x_akoko

CVE-2026-28414.yaml
7.5Score

CVSS Metrics

CVSS Vector:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CVE ID:
cve-2026-28414
CWE ID:
cwe-36

References

https://github.com/gradio-app/gradio/security/advisories/GHSA-39mp-8hj3-5c49https://nvd.nist.gov/vuln/detail/CVE-2026-28414

Remediation Steps

Upgrade to version 6.7 or later.