CVE-2026-28414Disclosure(gradio_project / gradio)

LOWCVSS 7.5 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Gradio is an open-source Python package designed for quick prototyping. Prior to version 6.7, Gradio apps running on Window with Python 3.13+ are vulnerable to an absolute path traversal issue that enables unauthenticated attackers to read arbitrary files from the file system. Python 3.13+ changed the definition of `os.path.isabs` so that root-relative paths like `/windows/win.ini` on Windows are no longer considered absolute paths, resulting in a vulnerability in Gradio's logic for joining paths safely. This can be exploited by unauthenticated attackers to read arbitrary files from the Gradio server, even when Gradio is set up with authentication. Version 6.7 fixes the issue.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-36CWE-22

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • gradio

Threat summary

  • 4 mentions across 4 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 3 signals
  • Disclosure: 3 classified signals
  • General: 1 classified signal
  • Peaked 3d ago at 1 mentions (2026-02-28); latest day: 1
  • 4 total mentions across 4 days

Affected systems

Products
gradio

Deep dive

Activity timeline4 mentions / 4d
00111Mentions · 2026-02-28: 1Mentions · 2026-03-02: 1Mentions · 2026-03-04: 1Mentions · 2026-03-31: 1Technical Details · 2026-03-02: 1Technical Details · 2026-03-04: 1Technical Details · 2026-03-31: 102-2803-0203-0403-31
Signal classification2 categories
Disclosure
375.0%
General
125.0%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-02-281
General1
2026-03-021
Disclosure1
2026-03-041
Disclosure1
2026-03-311
Disclosure1
Full discourse4 posts
  • Rey Bango 🇺🇦🌻@reybango
    Disclosure

    Our research team, @Horizon3Attack, discovered CVE-2026-28414 an unauthenticated file read vulnerability in Gradio apps running on Windows with Python 3.13+ — and it’s deceptively simple. https://www.linkedin.com/feed/update/urn:li:activity:7434311741011906561/

    Post summary

    The LinkedIn post announces the discovery of CVE-2026‑28414, describing it as an unauthenticated file‑read vulnerability in Gradio applications running on Windows with Python 3.13 or newer.

    0601441.6K
    22.6K followersView on X
  • pdnuclei-bot@pdnuclei_bot
    Disclosure

    🚨 CVE-2026-28414 - high 🚨 Gradio - Absolute Path Traversal > Gradio < 6.7 on Windows with Python 3.13+ contains an absolute path traversal caused ... 👾 https://cloud.projectdiscovery.io/library/CVE-2026-28414 @pdnuclei #NucleiTemplates #cve

    Post summary

    The post announces CVE‑2026‑28414 as a high‑severity absolute path traversal in Gradio versions before 6.7 on Windows, provides a link for more details, but does not disclose any PoC, exploit code, patch, or active exploitation.

    00012127
    905 followersView on X
  • CRAC Learning - Tech@cracbot
    Disclosure

    CVE-2026-28414 (CVSS:7.5, HIGH) is Undergoing Analysis. Gradio is an open-source Python package designed for quick prototyping. Prior to version 6.7, Gradio apps running on Win..https://nvd.nist.gov/vuln/detail/CVE-2026-28414 #cybersecurityawareness #cybersecurity #CVE #infosec #hacker #nvd #mitre

    Post summary

    CVE-2026-28414 is a high‑severity vulnerability in Gradio versions before 6.7, currently under analysis with no public exploit or patch disclosed.

    0000048
    173 followersView on X
  • CVE@CVEnew
    General

    CVE-2026-28414 Gradio is an open-source Python package designed for quick prototyping. Prior to version 6.7, Gradio apps running on Window with Python 3.13+ are vulnerable to an abs… https://www.cve.org/CVERecord?id=CVE-2026-28414

    Post summary

    The text references CVE-2026-28414 in Gradio but offers only a brief, incomplete mention of the vulnerability without details on exploitation, mitigation, or proof of concept.

    00000148
    56.6K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appgradio_projectgradio-python-

Explore more