Зацепка
Gradio apps often expose file-serving features around demos, model outputs, and shared UI assets. The advisory is tied to a specific Windows and Python runtime combination, so repo scans separate plain dependency evidence from dependency evidence plus matching runtime configuration.
Как это работает
The repo check looks for the PyPI `gradio` package in Python dependency manifests and lockfiles, then checks deployment files such as Dockerfiles, GitHub Actions workflows, Python version files, and project config for strong Windows and Python 3.13+ indicators.
Радиус поражения
If an affected Gradio runtime is deployed on Windows with Python 3.13 or newer and exposes the vulnerable file-serving path, unauthenticated users may be able to read files that the Gradio process can access. A repo match should drive dependency remediation and runtime verification before anyone treats it as confirmed arbitrary file read.
// что проверяет fixvibe
Что проверяет FixVibe
FixVibe repo scans look for high-confidence security patterns and dependency risk in source context. Reports identify the affected area and recommended fix. For check-specific questions about exact detection heuristics, active payload details, or source-code rule patterns, contact support@fixvibe.app.
Железные защиты
Upgrade `gradio` to 6.7.0 or newer, regenerate the active Python lockfile, and rebuild every app, worker, notebook, virtualenv, package cache, or container image that installs it. Confirm the deployed runtime version after rebuild, especially for Windows and Python 3.13+ deployments, and keep any Gradio sharing/file-serving surface restricted to trusted exposure while rollout completes.
