id: PYSEC-2024-261 published: "2024-02-05T23:15:08.190Z" modified: "2024-11-21T08:47:54.250Z" aliases: - CVE-2024-0964 - GHSA-f3h9-8phc-6gvh details: A local file include could be remotely triggered in Gradio due to a vulnerable user-supplied JSON value in an API request. affected: - package: name: gradio ecosystem: PyPI purl: pkg:pypi/gradio references: - type: FIX url: https://github.com/gradio-app/gradio/commit/d76bcaaaf0734aaf49a680f94ea9d4d22a602e70 - type: EVIDENCE url: https://huntr.com/bounties/25e25501-5918-429c-8541-88832dfd3741 - type: ADVISORY url: https://github.com/advisories/GHSA-f3h9-8phc-6gvh severity: - type: CVSS_V3 score: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L