Known CVE
Gradio - Absolute Path Traversal
Gradio < 6.7 on Windows with Python 3.13+ contains an absolute path traversal caused by incorrect path validation in path joining logic, letting unauthenticated attackers read arbitrary files from the server.
CVE-2026-28414
High2026CVSS 7.5CWE-36
cve2026 · gradio · lfi · traversal · unauth · windows · vkev
Verified scans run this check after you prove you own the site.
All known CVEsView the checks catalogNational Vulnerability Database
Scan a website