FixVibe

// código / holofote

Gradio Windows Python Path Traversal Advisory

Gradio apps served from Windows on Python 3.13+ can leak files the app process can read.

What it is

Gradio apps often expose file-serving features around demos, model outputs, and shared UI assets. This advisory only bites on one runtime combination, Windows with Python 3.13 or newer, which is exactly the setup a quick local-to-public demo tends to use.

How it happens

CVE-2026-28414 is an absolute-path traversal in Gradio's file serving, fixed in Gradio 6.7.0. On Windows with Python 3.13 or newer, a request for an absolute path can slip past the check that keeps file serving inside the app's allowed directories.

What an attacker gets

If an affected Gradio app runs on Windows with Python 3.13 or newer and is reachable from the internet, unauthenticated users may be able to read any file the Gradio process can access, including environment files, model weights, and API keys.

// what fixvibe reports

What FixVibe reports

Runs when you connect a GitHub repository, on Pro and above. Each finding shows the file and line, its severity and fix steps you can paste into your AI coding tool.

How to fix it

Upgrade `gradio` to 6.7.0 or newer, regenerate the active Python lockfile, and rebuild every app, worker, notebook, virtualenv, package cache, or container image that installs it. Confirm the deployed runtime version after rebuild, especially for Windows and Python 3.13+ deployments, and keep any Gradio sharing/file-serving surface restricted to trusted exposure while rollout completes.

// rode no seu próprio app

Continue publicando enquanto o FixVibe vigia.

Connect a GitHub repo to check its code, dependencies and workflows.

Código fonte
198
testes nessa categoria
módulos
155
checks dedicados de código fonte
GitHub repos
190+
checks on each connected repo
Connect GitHub →

// checks atuais · fixes práticos · publique com confiança

Gradio Windows Python Path Traversal Advisory: what it is and how to fix it · FixVibe