PyPI package intelligence
gradio Known Exploited Vulnerabilities
Track evidence-backed exploitation affecting the PyPI package gradio, including the gap beyond CISA KEV, confidence assessments, and sensor observations.
- Total KEVs
- 2
- Known exploited vulnerabilities affecting gradio
- In CISA KEV
- 0
- Records also listed in the official catalog
- Beyond CISA KEV
- 2
- Additional exploited vulnerabilities absent from CISA KEV
- Sensor Observed
- 0
- gradio KEVs with sensor-observed exploitation activity
Review gradio exploitation against the versions you run
Two of the two exploited gradio vulnerabilities tracked here are not in CISA KEV.
- 0%
- Covered by CISA
- 100%
- Beyond CISA
Attested gradio vulnerabilities
2 known exploited vulnerabilities affecting this package.
| Vulnerability | CISA KEV | Added |
|---|---|---|
|
CVE-2024-4325
Server-Side Request Forgery (SSRF) in gradio-app/gradio |
Beyond CISA | 05 Oct 2025 |
|
CVE-2024-1561
Arbitrary Local File Read via Component Method Invocation in gradio-app/gradio |
Beyond CISA | 05 Oct 2025 |
Recurring weakness patterns
Path Traversal: '\..\filename' and Server-Side Request Forgery (SSRF) account for mapped occurrences across this gradio KEV portfolio.