← Vulnerability feed

Vulnerability record · CVE-2024-1728 · published 10 April 2024

CVE-2024-1728: Gradio UploadButton path traversal allows arbitrary file read

Gradio Project · Gradio

Gradio's UploadButton component fails to properly validate user-supplied file paths, allowing path traversal through the /queue/join endpoint. An unauthenticated attacker can read arbitrary files on the server filesystem, including private SSH keys, and the flaw may escalate to remote code execution. The issue is patched upstream.

7.5 CVSS 3.1 High EPSS 85% · top 0.3% CWE-22 · Path traversal
7.5CVSS 3.1 base score
85%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
4References, 2 tagged exploit
17 Jun 2026Last modified by NVD

Description

gradio-app/gradio is vulnerable to a local file inclusion vulnerability due to improper validation of user-supplied input in the UploadButton component. Attackers can exploit this vulnerability to read arbitrary files on the filesystem, such as private SSH keys, by manipulating the file path in the request to the `/queue/join` endpoint. This issue could potentially lead to remote code execution. The vulnerability is present in the handling of file upload paths, allowing attackers to redirect file uploads to unintended locations on the server.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 18 September 2026. Confidence: high.

high priorityUnauthenticated network-reachable arbitrary file read with a very high EPSS score and public exploit reference, though not yet in KEV.

What it is

Gradio's UploadButton component fails to properly validate user-supplied file paths, allowing path traversal through the /queue/join endpoint. An unauthenticated attacker can read arbitrary files on the server filesystem, including private SSH keys, and the flaw may escalate to remote code execution. The issue is patched upstream.

Impact

An attacker gains read access to any file the Gradio process can reach, exposing credentials and keys, with a stated potential path to remote code execution. This can lead to full server compromise depending on what is readable and writable.

Attack surface

Reached over the network via the /queue/join endpoint with no authentication and no user interaction required, per the CVSS vector AV:N/AC:L/PR:N/UI:N. Any internet- or network-exposed Gradio instance with the affected UploadButton handling is in scope.

Exploitation

Not listed in CISA KEV, but EPSS is very high at 0.854 (99.7th percentile) and a public exploit reference exists via the huntr bounty, indicating active interest and likely weaponization.

What to do

  • Apply the upstream patch commit 16fbe9cd0cffa9f2a824a0165beb43446114eec7 or upgrade to a fixed Gradio release.
  • Restrict network access to Gradio endpoints such as /queue/join to trusted clients; do not expose Gradio apps directly to the internet.
  • Run the Gradio service under a least-privilege account with no access to sensitive files like SSH keys or cloud credentials.
  • Validate and canonicalize all user-supplied upload paths server-side, rejecting traversal sequences and paths outside the intended upload directory.

Detection

  • Monitor requests to /queue/join for path traversal patterns such as ../ or encoded variants in file path parameters.
  • Alert on the Gradio process reading files outside its expected upload or application directories, especially SSH keys or credential stores.
  • Review web logs for anomalous file path values in upload-related requests from single or untrusted source IPs.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2024-1728 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2024-39236Gradio project gradio code injection vulnerabilityGradio v4.36.1 was discovered to contain a code injection vulnerability via the component /gradio/component_meta.py. This vulnerability is triggered …EPSS 0.87%9.8CVE-2023-25823Gradio project gradio hard-coded credentials vulnerabilityGradio is an open-source Python library to build machine learning and data science demos and web applications. Versions prior to 3.13.1 contain Use o…EPSS 0.55%9.4CVE-2024-0964Gradio project gradio path traversal vulnerabilityA local file include could be remotely triggered in Gradio due to a vulnerable user-supplied JSON value in an API request.EPSS 0.96%9.1CVE-2024-4253Gradio project gradio os command injection vulnerabilityA command injection vulnerability exists in the gradio-app/gradio repository, specifically within the 'test-functional.yml' workflow. The vulnerabili…EPSS 1.7%9.1CVE-2023-34239Gradio project gradio improper input validation vulnerabilityGradio is an open-source Python library that is used to build machine learning and data science. Due to a lack of path filtering Gradio does not prop…EPSS 0.65%8.8CVE-2022-24770Gradio project gradio csv injection vulnerability`gradio` is an open source framework for building interactive machine learning models and demos. Prior to version 2.8.11, `gradio` suffers from Impro…EPSS 1.3%8.7CVE-2026-49119Gradio project gradio path traversal vulnerabilityGradio before 6.16.0 contain a path traversal vulnerability in the FileExplorer component's preprocess() method that allows unauthenticated attackers…EPSS 0.93%8.7CVE-2025-23042Gradio project gradio improper authorization vulnerabilityGradio is an open-source Python package that allows quick building of demos and web application for machine learning models, API, or any arbitrary Py…EPSS 0.98%

Source: NIST National Vulnerability Database (record CVE-2024-1728), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.