Skip to content

Known CVE

Gradio - Absolute Path Traversal

Gradio < 6.7 on Windows with Python 3.13+ contains an absolute path traversal caused by incorrect path validation in path joining logic, letting unauthenticated attackers read arbitrary files from the server.

CVE-2026-28414

High2026CVSS 7.5CWE-36

cve2026 · gradio · lfi · traversal · unauth · windows · vkev

Verified scans run this check after you prove you own the site.

All known CVEsView the checks catalogNational Vulnerability Database

Scan a website