FixVibe

high

Gradio Absolute Path Traversal on Windows with Python 3.13+ (CVE-2026-28414)

Gradio versions before 6.7.0 can expose a path traversal risk on Windows with Python 3.13+. FixVibe GitHub repo scans flag affected Gradio dependencies and note when the repository targets that runtime.

CVE-2026-28414GHSA-39mp-8hj3-5c49CWE-22CWE-36

Gradio versions before 6.7.0 are affected by CVE-2026-28414 / GHSA-39mp-8hj3-5c49 when the app runs on Windows with Python 3.13 or newer [S1, S2]. Advisory sources list CWE-22 and CWE-36 path traversal, high severity, and Gradio 6.7.0 as the patched release [S1, S3].

Why it matters

Gradio apps often handle generated files, uploaded assets, model outputs, and shareable UI resources. When the affected dependency and runtime conditions line up, the file-serving boundary can expose files that the Gradio process can access. That can turn a demo or internal tool into a sensitive-file exposure path, especially when secrets, configuration, or model artifacts live on the same host [S2, S3].

Covered by FixVibe

FixVibe's GitHub repo scans flag Python projects whose dependencies can resolve Gradio below 6.7.0, and note when the repository also targets Windows with Python 3.13 or newer, the runtime this advisory depends on.

What to fix

Upgrade Gradio to 6.7.0 or newer in the dependency source that controls deployment, then regenerate the active lockfile or constraints file. Rebuild every Gradio app, worker, notebook, virtualenv, package cache, Windows host, or container image that can install the affected wheel. If the app is deployed on Windows with Python 3.13 or newer, prioritize that rollout and verify the deployed runtime version after rebuild [S2, S4].

Keep Gradio sharing and file-serving surfaces limited to intended users and trusted networks while the upgrade rolls out. If an affected deployment was exposed, review access logs and host/file permissions using normal operational review rather than proof-of-exploit requests.

How to verify safely

Use dependency-tree and runtime-version checks such as pip show gradio, pip freeze, poetry show gradio, pipenv graph, or a package-manager equivalent. For deployed Windows/Python 3.13+ environments, verify the actual OS image or runner, Python version, rebuilt artifact, and Gradio version. Then rerun the FixVibe GitHub repo scan.

Do not verify by requesting file-serving routes with traversal input, reading system files, collecting secrets, or adding exploit fixtures to tests, tickets, docs, or examples.