gradio-app/gradio
cpe:2.3:a:gradio_project:gradio:*:*:*:*:python:*:*
- >= 0, < 0.0.0.0
A medium-severity open redirect vulnerability has been identified in the latest version of Gradio. This issue allows attackers to redirect users to malicious websites by exploiting URL encoding. The vulnerability can be triggered by sending a crafted request to the application, which then responds with a 302 redirect to an attacker-controlled site.
Exploitation of this vulnerability can lead to unauthorized redirection of users to malicious websites.
To reproduce this vulnerability, send a GET request to the Gradio application with a URL-encoded target, such as 'http://google.com'. The application will respond with a 302 redirect to the encoded URL, effectively redirecting the user to the specified site.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.