CVE-2024-4941
📛 CVE Title
Local File Inclusion in JSON component in gradio-app/gradio
Description
A local file inclusion vulnerability exists in the JSON component of gradio-app/gradio version 4.25. The vulnerability arises from improper input validation in the `postprocess()` function within `gradio/components/json_component.py`, where a user-controlled string is parsed as JSON. If the parsed JSON object contains a `path` key, the specified file is moved to a temporary directory, making it possible to retrieve it later via the `/file=..` endpoint. This issue is due to the `processing_utils.move_files_to_cache()` function traversing any object passed to it, looking for a dictionary with a `path` key, and then copying the specified file to a temporary directory. The vulnerability can be exploited by an attacker to read files on the remote system, posing a significant security risk.
Overview
- State
- PUBLISHED
- Assigner (CNA)
- @huntr_ai
- CVSS severity
- HIGH
- CVSS score
- 7.5 / 10
- CVSS vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N- Effective score
- 7.5 / 10 HIGH source: CNA overview
- CWE(s)
-
CWE-22 - Reserved
- 2024-05-15
- Published
- 2024-06-06 19:55 UTC
- Last updated
- 2025-10-15 14:49 UTC
- Source
- https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2024/4xxx/CVE-2024-4941.json
- Linked Threat
- CVE-2024-4941 — Local File Inclusion in JSON component in gradio-app/gradio
European Union Vulnerability Database ENISA EUVD
ENISA's official EU repository for curated vulnerability intelligence. Carries a separate identifier (EUVD-YYYY-NNNN) and frequently exposes an earlier-published description + CVSS than NVD does.
- EUVD ID
-
EUVD-2024-0063 - Assigner
- @huntr_ai
- Published
- Jun 6, 2024, 5:55:11 PM
- Updated
- Oct 15, 2025, 12:49:40 PM
- EUVD base score (CVSS 3.0)
-
7.5 / 10
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N - EUVD-reported EPSS
- 0.6900
- Vendors
- gradio-app
- Products
-
gradio-app/gradio (unspecified <4.31.4)
- Aliases
-
GHSA-6v6g-j5fq-hpvw,PYSEC-2024-184
ENISA description: A local file inclusion vulnerability exists in the JSON component of gradio-app/gradio version 4.25. The vulnerability arises from improper input validation in the `postprocess()` function within `gradio/components/json_component.py`, where a user-controlled string is parsed as JSON. If the parsed JSON object contains a `path` key, the specified file is moved to a temporary directory, making it possible to retrieve it later via the `/file=..` endpoint. This issue is due to the `processing_utils.move_files_to_cache()` function traversing any object passed to it, looking for a dictionary with a `path` key, and then copying the specified file to a temporary directory. The vulnerability can be exploited by an attacker to read files on the remote system, posing a significant security risk.
Affected products (1)
| Vendor | Product | Versions | Platforms |
|---|---|---|---|
| gradio-app | gradio-app/gradio |
unspecified (affected)
|
— |
Vendor references (2)
References embedded in the original CVE record by the assigning CNA.
Web references (0)
DuckDuckGo results ranked by threat-intel / vendor advisory domains. Generated by the 🔎 Find references (web) button above — same flow as the Remediations search.
No web references attached yet.
Remediations (18)
Remediations are stored against the linked Threat row; the list below is deduplicated across both pages.
-
web:www.youtube.com
LIVE book review with The Fabric Patch !! Once a month join on our reading journeys! 1.2K views • Streamed 1 year ago
2026-08-05 14:57 UTC -
web:fix-it-up.fandom.com
Fix It Up is a Roblox car repair simulator game developed by .workspace. Players buy or find broken cars, repair damaged parts, customize them, and sell them for profit.
2026-08-05 14:57 UTC -
web:hypixel.net
All SkyBlock Patch Notes can be found here! You can click the Watch button in this section to be alerted when new Patch Notes are released!
2026-08-05 14:57 UTC -
web:seeclickfix.com
Sign up for a CivicPlus account.
2026-08-05 14:57 UTC -
web:support.microsoft.com
Windows 11; Windows 10; Updating the Bluetooth driver can help resolve connection, pairing, or detection issues. Use the following steps to update the driver. Update the Bluetooth
2026-08-05 14:57 UTC -
web:www.callofduty.com
Contract Spawning. Increased the minimum distance at which Contracts of the same type will spawn. Added a minimum horizontal spacing requirement between Contracts to improve visib
2026-08-05 14:57 UTC -
web:www.drugs.com
Fentanyl transdermal skin patch (skin patch ): side effects, dosage, interactions, FAQs, reviews. Used for: anesthesia, anesthetic adjunct, breakthrough pain, chronic ...
2026-08-05 14:57 UTC -
web:www.pesmodding.com
PES Modding is a sharing content for Pro Evolution Soccer (PES) community - Patches, Tools, Kits, Stadiums, and many other Mods, News & Updates.
2026-08-05 14:57 UTC -
web:web.whatsapp.com
Log in to WhatsApp Web for simple, reliable and private messaging on your desktop. Send and receive messages and files with ease, all for free.
2026-05-22 10:39 UTC -
web:www.secure.com
Learn the difference between vulnerability remediation and mitigation , and how a risk-based strategy can strengthen your security posture.
2026-05-22 10:39 UTC -
web:www.cisa.gov
For the benefit of the cybersecurity community and network defenders—and to help every organization better manage vulnerabilities and keep pace with threat activity—CISA maintains the authoritative source of vulnerabilities that have been exploited in the wild. Organizations should use the KEV catalog as an input to their vulnerability management prioritization framework.
2026-05-22 10:39 UTC -
web:www.virustotal.com
Streamline your investigations with Google Threat Intelligence Agentic and the new Dark Web (DDW) module. Perform hunting and pivoting across forums using natural language or specific modifiers. Bridge threat actor identities and map global operations easy.
2026-05-22 10:39 UTC -
web:www.ibm.com
IBM MQ provides regular updates containing new function and fixes. This document contains lists of available fixes for the IBM MQ 9.4 initial release and subsequent Continuous Delivery (CD) releases and CD Cumulative Security Updates (CSUs), with the most recent release or update at the top.
2026-05-22 10:39 UTC -
web:nvd.nist.gov
The NVD is the U.S. government repository of standards based vulnerability management data represented using the Security Content Automation Protocol (SCAP). This data enables automation of vulnerability management, security measurement, and compliance. The NVD includes databases of security checklist references, security-related software flaws, product names, and impact metrics. For ...
2026-05-22 10:39 UTC -
web:portal.msrc.microsoft.com
The Security Update Guide provides information on the latest Microsoft security updates, helping users understand and address potential vulnerabilities effectively.
2026-05-22 10:39 UTC -
web:robertsspaceindustries.com
Hi Everyone! Time again for another Hotfix Central thread to keep you all up to date on things going on outside of the normal patch cycle in SC Alpha 4.8 LIVE! This will be a living document of...
2026-05-22 10:39 UTC -
web:www.oracle.com
Critical Security Patch Updates Critical Security Patch Updates provide security patches for supported Oracle on-premises products. A Critical Security Patch Update provides targeted, high-priority security fixes in a smaller, more focused format, making them easier to apply with minimal disruption.
2026-05-22 10:39 UTC -
web:cybersecuritynews.com
The December 2024 Patch Tuesday update includes a fix for this vulnerability, and users are strongly advised to apply the patch immediately. Critical Remote Code Execution Vulnerabilities This month's patch includes fixes for CVE - 2024 -49116, a highly critical RCE vulnerability impacting multiple versions of Windows Server.
2026-05-22 10:39 UTC
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.
Raw JSON
The full cvelistV5 record. Download as CVE-2024-4941.json.
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2024-4941",
"options": [
{
"Exploitation": "poc"
},
{
"Automatable": "yes"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2025-03-20T18:13:53.877871Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2025-03-20T18:14:11.058Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
},
{
"providerMetadata": {
"dateUpdated": "2024-08-01T20:55:10.306Z",
"orgId": "af854a3a-2127-422b-91ae-364da2661108",
"shortName": "CVE"
},
"references": [
{
"tags": [
"x_transferred"
],
"url": "https://huntr.com/bounties/39889ce1-298d-4568-aecd-7ae40c2ca58e"
},
{
"tags": [
"x_transferred"
],
"url": "https://github.com/gradio-app/gradio/commit/ee1e2942e0a1ae84a08a05464e41c8108a03fa9c"
}
],
"title": "CVE Program Container"
}
],
"cna": {
"affected": [
{
"product": "gradio-app/gradio",
"vendor": "gradio-app",
"versions": [
{
"lessThan": "4.31.4",
"status": "affected",
"version": "unspecified",
"versionType": "custom"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "A local file inclusion vulnerability exists in the JSON component of gradio-app/gradio version 4.25. The vulnerability arises from improper input validation in the `postprocess()` function within `gradio/components/json_component.py`, where a user-controlled string is parsed as JSON. If the parsed JSON object contains a `path` key, the specified file is moved to a temporary directory, making it possible to retrieve it later via the `/file=..` endpoint. This issue is due to the `processing_utils.move_files_to_cache()` function traversing any object passed to it, looking for a dictionary with a `path` key, and then copying the specified file to a temporary directory. The vulnerability can be exploited by an attacker to read files on the remote system, posing a significant security risk."
}
],
"metrics": [
{
"cvssV3_0": {
"attackComplexity": "LOW",
"attackVector": "NETWORK",
"availabilityImpact": "NONE",
"baseScore": 7.5,
"baseSeverity": "HIGH",
"confidentialityImpact": "HIGH",
"integrityImpact": "NONE",
"privilegesRequired": "NONE",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
"version": "3.0"
}
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-22",
"description": "CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2025-10-15T12:49:40.335Z",
"orgId": "c09c270a-b464-47c1-9133-acb35b22c19a",
"shortName": "@huntr_ai"
},
"references": [
{
"url": "https://huntr.com/bounties/39889ce1-298d-4568-aecd-7ae40c2ca58e"
},
{
"url": "https://github.com/gradio-app/gradio/commit/ee1e2942e0a1ae84a08a05464e41c8108a03fa9c"
}
],
"source": {
"advisory": "39889ce1-298d-4568-aecd-7ae40c2ca58e",
"discovery": "EXTERNAL"
},
"title": "Local File Inclusion in JSON component in gradio-app/gradio"
}
},
"cveMetadata": {
"assignerOrgId": "c09c270a-b464-47c1-9133-acb35b22c19a",
"assignerShortName": "@huntr_ai",
"cveId": "CVE-2024-4941",
"datePublished": "2024-06-06T17:55:11.754Z",
"dateReserved": "2024-05-15T13:53:03.304Z",
"dateUpdated": "2025-10-15T12:49:40.335Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.1"
}