CVE-2024-8021

MEDIUM5.4EPSS 2.4%

Gradio Vulnerable to Open Redirect

Published: 3/20/2025Modified: 3/21/2025
Also known as:GHSA-7v2w-h4gh-w5cv

Description

An open redirect vulnerability exists in the latest version of gradio-app/gradio. The vulnerability allows an attacker to redirect users to a malicious website by URL encoding. This can be exploited by sending a crafted request to the application, which results in a 302 redirect to an attacker-controlled site.

Affected packages (1)

CVSS scores

SourceVersionSeverityVector
osvCVSS 3.1MEDIUM5.4CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N

References (3)