s2
--:--:--UTC

Searching APEX

Starting…

  1. Searching Threats, IOCs & Threat Intelligence locally
  2. Querying external providers
  3. Asking AI Forensic Validator
  4. Creating new entry from validated hit

0s elapsed

CVE-2024-4941

📛 CVE Title

Local File Inclusion in JSON component in gradio-app/gradio

Description

A local file inclusion vulnerability exists in the JSON component of gradio-app/gradio version 4.25. The vulnerability arises from improper input validation in the `postprocess()` function within `gradio/components/json_component.py`, where a user-controlled string is parsed as JSON. If the parsed JSON object contains a `path` key, the specified file is moved to a temporary directory, making it possible to retrieve it later via the `/file=..` endpoint. This issue is due to the `processing_utils.move_files_to_cache()` function traversing any object passed to it, looking for a dictionary with a `path` key, and then copying the specified file to a temporary directory. The vulnerability can be exploited by an attacker to read files on the remote system, posing a significant security risk.

Overview

State
PUBLISHED
Assigner (CNA)
@huntr_ai
CVSS severity
HIGH
CVSS score
CVSS 7.5 / 10 7.5 7.5 / 10
CVSS vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Effective score
7.5 / 10 HIGH source: CNA overview
CWE(s)
CWE-22
Reserved
2024-05-15
Published
2024-06-06 19:55 UTC
Last updated
2025-10-15 14:49 UTC
Source
https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2024/4xxx/CVE-2024-4941.json
Linked Threat
CVE-2024-4941 — Local File Inclusion in JSON component in gradio-app/gradio

European Union Vulnerability Database ENISA EUVD

ENISA's official EU repository for curated vulnerability intelligence. Carries a separate identifier (EUVD-YYYY-NNNN) and frequently exposes an earlier-published description + CVSS than NVD does.

EUVD ID
EUVD-2024-0063
Assigner
@huntr_ai
Published
Jun 6, 2024, 5:55:11 PM
Updated
Oct 15, 2025, 12:49:40 PM
EUVD base score (CVSS 3.0)
7.5 / 10
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
EUVD-reported EPSS
0.6900
Vendors
gradio-app
Products
gradio-app/gradio (unspecified <4.31.4)
Aliases
GHSA-6v6g-j5fq-hpvw, PYSEC-2024-184

ENISA description: A local file inclusion vulnerability exists in the JSON component of gradio-app/gradio version 4.25. The vulnerability arises from improper input validation in the `postprocess()` function within `gradio/components/json_component.py`, where a user-controlled string is parsed as JSON. If the parsed JSON object contains a `path` key, the specified file is moved to a temporary directory, making it possible to retrieve it later via the `/file=..` endpoint. This issue is due to the `processing_utils.move_files_to_cache()` function traversing any object passed to it, looking for a dictionary with a `path` key, and then copying the specified file to a temporary directory. The vulnerability can be exploited by an attacker to read files on the remote system, posing a significant security risk.

EUVD references (2)

Affected products (1)

VendorProductVersionsPlatforms
gradio-app gradio-app/gradio unspecified (affected)

Vendor references (2)

References embedded in the original CVE record by the assigning CNA.

Web references (0)

DuckDuckGo results ranked by threat-intel / vendor advisory domains. Generated by the 🔎 Find references (web) button above — same flow as the Remediations search.

No web references attached yet.

Remediations (18)

Remediations are stored against the linked Threat row; the list below is deduplicated across both pages.

  • web:www.youtube.com

    LIVE book review with The Fabric Patch !! Once a month join on our reading journeys! 1.2K views • Streamed 1 year ago

    2026-08-05 14:57 UTC
  • web:fix-it-up.fandom.com

    Fix It Up is a Roblox car repair simulator game developed by .workspace. Players buy or find broken cars, repair damaged parts, customize them, and sell them for profit.

    2026-08-05 14:57 UTC
  • web:hypixel.net

    All SkyBlock Patch Notes can be found here! You can click the Watch button in this section to be alerted when new Patch Notes are released!

    2026-08-05 14:57 UTC
  • web:seeclickfix.com

    Sign up for a CivicPlus account.

    2026-08-05 14:57 UTC
  • web:support.microsoft.com

    Windows 11; Windows 10; Updating the Bluetooth driver can help resolve connection, pairing, or detection issues. Use the following steps to update the driver. Update the Bluetooth

    2026-08-05 14:57 UTC
  • web:www.callofduty.com

    Contract Spawning. Increased the minimum distance at which Contracts of the same type will spawn. Added a minimum horizontal spacing requirement between Contracts to improve visib

    2026-08-05 14:57 UTC
  • web:www.drugs.com

    Fentanyl transdermal skin patch (skin patch ): side effects, dosage, interactions, FAQs, reviews. Used for: anesthesia, anesthetic adjunct, breakthrough pain, chronic ...

    2026-08-05 14:57 UTC
  • web:www.pesmodding.com

    PES Modding is a sharing content for Pro Evolution Soccer (PES) community - Patches, Tools, Kits, Stadiums, and many other Mods, News & Updates.

    2026-08-05 14:57 UTC
  • web:web.whatsapp.com

    Log in to WhatsApp Web for simple, reliable and private messaging on your desktop. Send and receive messages and files with ease, all for free.

    2026-05-22 10:39 UTC
  • web:www.secure.com

    Learn the difference between vulnerability remediation and mitigation , and how a risk-based strategy can strengthen your security posture.

    2026-05-22 10:39 UTC
  • web:www.cisa.gov

    For the benefit of the cybersecurity community and network defenders—and to help every organization better manage vulnerabilities and keep pace with threat activity—CISA maintains the authoritative source of vulnerabilities that have been exploited in the wild. Organizations should use the KEV catalog as an input to their vulnerability management prioritization framework.

    2026-05-22 10:39 UTC
  • web:www.virustotal.com

    Streamline your investigations with Google Threat Intelligence Agentic and the new Dark Web (DDW) module. Perform hunting and pivoting across forums using natural language or specific modifiers. Bridge threat actor identities and map global operations easy.

    2026-05-22 10:39 UTC
  • web:www.ibm.com

    IBM MQ provides regular updates containing new function and fixes. This document contains lists of available fixes for the IBM MQ 9.4 initial release and subsequent Continuous Delivery (CD) releases and CD Cumulative Security Updates (CSUs), with the most recent release or update at the top.

    2026-05-22 10:39 UTC
  • web:nvd.nist.gov

    The NVD is the U.S. government repository of standards based vulnerability management data represented using the Security Content Automation Protocol (SCAP). This data enables automation of vulnerability management, security measurement, and compliance. The NVD includes databases of security checklist references, security-related software flaws, product names, and impact metrics. For ...

    2026-05-22 10:39 UTC
  • web:portal.msrc.microsoft.com

    The Security Update Guide provides information on the latest Microsoft security updates, helping users understand and address potential vulnerabilities effectively.

    2026-05-22 10:39 UTC
  • web:robertsspaceindustries.com

    Hi Everyone! Time again for another Hotfix Central thread to keep you all up to date on things going on outside of the normal patch cycle in SC Alpha 4.8 LIVE! This will be a living document of...

    2026-05-22 10:39 UTC
  • web:www.oracle.com

    Critical Security Patch Updates Critical Security Patch Updates provide security patches for supported Oracle on-premises products. A Critical Security Patch Update provides targeted, high-priority security fixes in a smaller, more focused format, making them easier to apply with minimal disruption.

    2026-05-22 10:39 UTC
  • web:cybersecuritynews.com

    The December 2024 Patch Tuesday update includes a fix for this vulnerability, and users are strongly advised to apply the patch immediately. Critical Remote Code Execution Vulnerabilities This month's patch includes fixes for CVE - 2024 -49116, a highly critical RCE vulnerability impacting multiple versions of Windows Server.

    2026-05-22 10:39 UTC

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.

Raw JSON

The full cvelistV5 record. Download as CVE-2024-4941.json.

{
  "containers": {
    "adp": [
      {
        "metrics": [
          {
            "other": {
              "content": {
                "id": "CVE-2024-4941",
                "options": [
                  {
                    "Exploitation": "poc"
                  },
                  {
                    "Automatable": "yes"
                  },
                  {
                    "Technical Impact": "partial"
                  }
                ],
                "role": "CISA Coordinator",
                "timestamp": "2025-03-20T18:13:53.877871Z",
                "version": "2.0.3"
              },
              "type": "ssvc"
            }
          }
        ],
        "providerMetadata": {
          "dateUpdated": "2025-03-20T18:14:11.058Z",
          "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "shortName": "CISA-ADP"
        },
        "title": "CISA ADP Vulnrichment"
      },
      {
        "providerMetadata": {
          "dateUpdated": "2024-08-01T20:55:10.306Z",
          "orgId": "af854a3a-2127-422b-91ae-364da2661108",
          "shortName": "CVE"
        },
        "references": [
          {
            "tags": [
              "x_transferred"
            ],
            "url": "https://huntr.com/bounties/39889ce1-298d-4568-aecd-7ae40c2ca58e"
          },
          {
            "tags": [
              "x_transferred"
            ],
            "url": "https://github.com/gradio-app/gradio/commit/ee1e2942e0a1ae84a08a05464e41c8108a03fa9c"
          }
        ],
        "title": "CVE Program Container"
      }
    ],
    "cna": {
      "affected": [
        {
          "product": "gradio-app/gradio",
          "vendor": "gradio-app",
          "versions": [
            {
              "lessThan": "4.31.4",
              "status": "affected",
              "version": "unspecified",
              "versionType": "custom"
            }
          ]
        }
      ],
      "descriptions": [
        {
          "lang": "en",
          "value": "A local file inclusion vulnerability exists in the JSON component of gradio-app/gradio version 4.25. The vulnerability arises from improper input validation in the `postprocess()` function within `gradio/components/json_component.py`, where a user-controlled string is parsed as JSON. If the parsed JSON object contains a `path` key, the specified file is moved to a temporary directory, making it possible to retrieve it later via the `/file=..` endpoint. This issue is due to the `processing_utils.move_files_to_cache()` function traversing any object passed to it, looking for a dictionary with a `path` key, and then copying the specified file to a temporary directory. The vulnerability can be exploited by an attacker to read files on the remote system, posing a significant security risk."
        }
      ],
      "metrics": [
        {
          "cvssV3_0": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "NONE",
            "baseScore": 7.5,
            "baseSeverity": "HIGH",
            "confidentialityImpact": "HIGH",
            "integrityImpact": "NONE",
            "privilegesRequired": "NONE",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
            "version": "3.0"
          }
        }
      ],
      "problemTypes": [
        {
          "descriptions": [
            {
              "cweId": "CWE-22",
              "description": "CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')",
              "lang": "en",
              "type": "CWE"
            }
          ]
        }
      ],
      "providerMetadata": {
        "dateUpdated": "2025-10-15T12:49:40.335Z",
        "orgId": "c09c270a-b464-47c1-9133-acb35b22c19a",
        "shortName": "@huntr_ai"
      },
      "references": [
        {
          "url": "https://huntr.com/bounties/39889ce1-298d-4568-aecd-7ae40c2ca58e"
        },
        {
          "url": "https://github.com/gradio-app/gradio/commit/ee1e2942e0a1ae84a08a05464e41c8108a03fa9c"
        }
      ],
      "source": {
        "advisory": "39889ce1-298d-4568-aecd-7ae40c2ca58e",
        "discovery": "EXTERNAL"
      },
      "title": "Local File Inclusion in JSON component in gradio-app/gradio"
    }
  },
  "cveMetadata": {
    "assignerOrgId": "c09c270a-b464-47c1-9133-acb35b22c19a",
    "assignerShortName": "@huntr_ai",
    "cveId": "CVE-2024-4941",
    "datePublished": "2024-06-06T17:55:11.754Z",
    "dateReserved": "2024-05-15T13:53:03.304Z",
    "dateUpdated": "2025-10-15T12:49:40.335Z",
    "state": "PUBLISHED"
  },
  "dataType": "CVE_RECORD",
  "dataVersion": "5.1"
}