⚠ Withdrawn by GitHub Security Advisories

Withdrawn: October 17, 2025

GHSA-9v2f-6vcg-3hgvCriticalCVSS 9.8

Withdrawn Advisory: Gradio was discovered to contain a code injection vulnerability via the component /gradio/component_meta.py

Published
July 1, 2024
Last Modified
June 5, 2026

🔗 CVE IDs covered (1)

📋 Description

Withdrawn Advisory

This advisory has been withdrawn because the it only affects a user who runs specifically crafted code that happens to use gradio library. More information can be found here.

Original Description

Gradio v4.36.1 was discovered to contain a code injection vulnerability via the component /gradio/component_meta.py. This vulnerability is triggered via a crafted input.

🎯 Affected products1

  • pip/Gradio:= 4.36.1

🔗 References (6)