FixVibe

// 코드 / 스포트라이트

Gradio Windows Python Path Traversal Advisory

Gradio apps served from Windows on Python 3.13+ can leak files the app process can read.

What it is

Gradio apps often expose file-serving features around demos, model outputs, and shared UI assets. This advisory only bites on one runtime combination, Windows with Python 3.13 or newer, which is exactly the setup a quick local-to-public demo tends to use.

How it happens

CVE-2026-28414 is an absolute-path traversal in Gradio's file serving, fixed in Gradio 6.7.0. On Windows with Python 3.13 or newer, a request for an absolute path can slip past the check that keeps file serving inside the app's allowed directories.

What an attacker gets

If an affected Gradio app runs on Windows with Python 3.13 or newer and is reachable from the internet, unauthenticated users may be able to read any file the Gradio process can access, including environment files, model weights, and API keys.

// what fixvibe reports

What FixVibe reports

Runs when you connect a GitHub repository, on Pro and above. Each finding shows the file and line, its severity and fix steps you can paste into your AI coding tool.

How to fix it

Upgrade `gradio` to 6.7.0 or newer, regenerate the active Python lockfile, and rebuild every app, worker, notebook, virtualenv, package cache, or container image that installs it. Confirm the deployed runtime version after rebuild, especially for Windows and Python 3.13+ deployments, and keep any Gradio sharing/file-serving surface restricted to trusted exposure while rollout completes.

// 내 앱에서 직접 실행해보세요

FixVibe가 지켜보는 동안 계속 배포하세요.

Connect a GitHub repo to check its code, dependencies and workflows.

소스 코드
198
이 카테고리에서 실행되는 테스트
모듈
155
전용 소스 코드 검사
GitHub repos
190+
checks on each connected repo
Connect GitHub →

// 최신 체크 · 실용적인 수정 · 자신 있게 배포

Gradio Windows Python Path Traversal Advisory: what it is and how to fix it · FixVibe