CVE-2025-48889 | Teknoloji dünyasından en güncel haberleri ve güvenlikle ilgili gelişmeleri takip edin.

Gradio is an open-source Python package that allows quick building of demos and web application for machine learning models, API, or any arbitrary Python functi…
Medium CVSS: 5.3

CVE-2025-48889

Gradio is an open-source Python package that allows quick building of demos and web application for machine learning models, API, or any arbitrary Python function. Prior to version 5.31.0, an arbitrary file copy vulnerability in Gradio's flagging feature allows unauthenticated attackers to copy any readable file from the server's filesystem. While attackers can't read these copied files, they can cause DoS by copying large files (like /dev/urandom) to fill disk space. This issue has been patched in version 5.31.0.
Vendor
Gradio Project
Product
Gradio
CWE
CWE-434
Yayın Tarihi
2025-05-30 06:15:28
Güncelleme
2025-08-26 16:28:02
Source Identifier
security-advisories@github.com
KEV Date Added
-

Kategoriler

Referanslar