FixVibe

// 代码 / 聚焦

Gradio Windows Python Path Traversal Advisory

Gradio apps served from Windows on Python 3.13+ can leak files the app process can read.

What it is

Gradio apps often expose file-serving features around demos, model outputs, and shared UI assets. This advisory only bites on one runtime combination, Windows with Python 3.13 or newer, which is exactly the setup a quick local-to-public demo tends to use.

How it happens

CVE-2026-28414 is an absolute-path traversal in Gradio's file serving, fixed in Gradio 6.7.0. On Windows with Python 3.13 or newer, a request for an absolute path can slip past the check that keeps file serving inside the app's allowed directories.

What an attacker gets

If an affected Gradio app runs on Windows with Python 3.13 or newer and is reachable from the internet, unauthenticated users may be able to read any file the Gradio process can access, including environment files, model weights, and API keys.

// what fixvibe reports

What FixVibe reports

Runs when you connect a GitHub repository, on Pro and above. Each finding shows the file and line, its severity and fix steps you can paste into your AI coding tool.

How to fix it

Upgrade `gradio` to 6.7.0 or newer, regenerate the active Python lockfile, and rebuild every app, worker, notebook, virtualenv, package cache, or container image that installs it. Confirm the deployed runtime version after rebuild, especially for Windows and Python 3.13+ deployments, and keep any Gradio sharing/file-serving surface restricted to trusted exposure while rollout completes.

// 在你自己的應用上跑一遍

放心继續發布,FixVibe 持續幫你看守風险。

Connect a GitHub repo to check its code, dependencies and workflows.

源代码
198
本類别中触發的测試
模塊
155
專属 源代码 检查
GitHub repos
190+
checks on each connected repo
Connect GitHub →

// 最新检查 · 实用修複 · 安心發布

Gradio Windows Python Path Traversal Advisory: what it is and how to fix it · FixVibe