HIGH
Command Injection in gradio-app/gradio
Published Dec 14, 2023
8.1
HIGHCVSS 3.1
EPSS 1.68%
Description
Command Injection in GitHub repository gradio-app/gradio prior to main.
Affected products
-
- Version unspecifiedStatusaffectedConstraints<main
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| Gradio-App | Gradio-App/gradio | n/a |
|
- < 4.14.0
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (2)
References (5)
- https://github.com/advisories/GHSA-gqvf-3hgp-5hxv Advisory
- https://github.com/gradio-app/gradio/commit/5b5af1899dd98d63e1f9b48a93601c2db1f56520 Patch
- https://github.com/pypa/advisory-database/tree/main/vulns/gradio/PYSEC-2023-255.yaml
- https://huntr.com/bounties/21d2ff0c-d43a-4afd-bb4d-049ee8da5b5c ExploitIssue TrackingPatchThird Party Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2023-6572
| Link | Providers | Tags |
|---|---|---|
| https://github.com/advisories/GHSA-gqvf-3hgp-5hxv | Advisory | |
| https://github.com/gradio-app/gradio/commit/5b5af1899dd98d63e1f9b48a93601c2db1f56520 | Patch | |
| https://github.com/pypa/advisory-database/tree/main/vulns/gradio/PYSEC-2023-255.yaml | ||
| https://huntr.com/bounties/21d2ff0c-d43a-4afd-bb4d-049ee8da5b5c | ExploitIssue TrackingPatchThird Party Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2023-6572 |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner @huntr_ai
Published Dec 14, 2023
Updated May 22, 2025
Reserved Dec 7, 2023
Link CVE-2023-6572
CISA Vulnrichment
GHSA-GQVF-3HGP-5HXV Updated May 22, 2025