Safety vulnerability ID: 71660
The information on this page was manually curated by our Cybersecurity Intelligence Team.
Affected versions of the gradio package are vulnerable to Server-Side Request Forgery (SSRF) due to insufficient validation of user-supplied URLs in the /proxy route. The vulnerability exists in the build_proxy_request function's inadequate checking of safe URLs, allowing attackers to manipulate the self.replica_urls set through the X-Direct-Url header in requests to the / and /config routes.
Latest version: 5.39.0
Python library for easily interacting with trained machine learning models
This vulnerability has no description
Scan your Python project for dependency vulnerabilities in two minutes
Scan your application