Skip to content

Make the `/file` and `/proxy` routes more secure

High
abidlabs published GHSA-3qqg-pgqq-3695 Jun 7, 2023

Package

pip gradio (pip)

Affected versions

<=3.33.1

Patched versions

3.34.0

Description

Impact

There are two separate security vulnerabilities here: (1) a security vulnerability that allows users to read arbitrary files on the machines that are running shared Gradio apps (2) the ability of users to use machines that are sharing Gradio apps to proxy arbitrary URLs

Patches

Both problems have been solved, please upgrade gradio to 3.34.0 or higher

Workarounds

Not possible to workaround except by taking down any shared Gradio apps

References

Relevant PRs:

Severity

High

CVE ID

CVE-2023-34239

Weaknesses

No CWEs

Credits