Withdrawn Advisory: Gradio was discovered to contain a code injection vulnerability via the component /gradio/component_meta.py
Critical severity
GitHub Reviewed
Published
Jul 1, 2024
to the GitHub Advisory Database
•
Updated Oct 17, 2025
Withdrawn
This advisory was withdrawn on Oct 17, 2025
Description
Published by the National Vulnerability Database
Jul 1, 2024
Published to the GitHub Advisory Database
Jul 1, 2024
Reviewed
Jul 1, 2024
Withdrawn
Oct 17, 2025
Last updated
Oct 17, 2025
Withdrawn Advisory
This advisory has been withdrawn because the it only affects a user who runs specifically crafted code that happens to use gradio library. More information can be found here.
Original Description
Gradio v4.36.1 was discovered to contain a code injection vulnerability via the component /gradio/component_meta.py. This vulnerability is triggered via a crafted input.
References