Informational scan, not a security audit. How this is computed.
API keys, passwords or tokens committed into the repo.
generic-api-key Detected a Generic API Key, potentially exposing access to various services and sensitive operations.Packages you depend on that have known security holes (CVEs).
CVE-2023-6572 Gradio Exposure of Sensitive Information to an Unauthorized Actor vulnerabilityCVE-2024-1728 Gradio allows users to access arbitrary filesCVE-2025-23042 Gradio Blocked Path ACL Bypass VulnerabilityCVE-2023-6730 transformers has a Deserialization of Untrusted Data vulnerabilityCVE-2026-44513 Diffusers: Diffusers: Arbitrary remote code execution via `trust_remote_code` bypassCVE-2026-45804 diffusers: Diffusers: Arbitrary code execution due to trust_remote_code guard bypassCVE-2023-51449 Gradio makes the `/file` secure against file traversal and server-side request forgery attacksCVE-2024-0964 Gradio Path Traversal vulnerabilityCVE-2024-1561 gradio vulnerable to Path TraversalCVE-2024-2206 gradio Server-Side Request Forgery vulnerabilityCVE-2024-34510 Gradio allows credential leakage on WindowsCVE-2024-47084 Gradios's CORS origin validation is not performed when the request has a cookieCVE-2024-47867 Gradio lacks integrity checking on the downloaded FRP clientCVE-2024-47870 Gradio has a race condition in update_root_in_config may redirect user trafficCVE-2024-47871 Gradio uses insecure communication between the FRP client and serverCVE-2024-4941 Local file inclusion in gradioCVE-2026-28414 Gradio is Vulnerable to Absolute Path Traversal on Windows with Python 3.13+CVE-2026-28416 Gradio: Gradio: Server-Side Request Forgery allows access to internal services via malicious Space loadingCVE-2026-48545 Gradio contains a cookie injection vulnerabilityCVE-2024-1183 gradio Server-Side Request Forgery vulnerabilityCVE-2024-1727 Gradio applications running locally vulnerable to 3rd party websites accessing routes and uploading filesCVE-2024-1729 Gradio apps vulnerable to timing attacks to guess passwordCVE-2024-47164 Gradio's `is_in_or_equal` function may be bypassedCVE-2024-47165 Gradio's CORS origin validation accepts the null originCVE-2024-47166 Gradio has a one-level read path traversal in `/custom_component`Your dependencies cross-checked against the OSV vulnerability database.
PYSEC-2023-255 Command Injection in GitHub repository gradio-app/gradio prior to main.PYSEC-2024-215 Gradio is an open-source Python package designed for quick prototyping. This vulnerability relates to **Server-Side Request Forgery (SSRF)** in the `/queue/join` endpoint. Gradio’s `async_save_url_to_PYSEC-2024-219 Gradio is an open-source Python package designed for quick prototyping. This vulnerability involves **insecure communication** between the FRP (Fast Reverse Proxy) client and server when Gradio's `shaPYSEC-2024-274 Gradio v4.36.1 was discovered to contain a code injection vulnerability via the component /gradio/component_meta.py. This vulnerability is triggered via a crafted input. NOTE: the supplier disputes thPYSEC-2024-321 A command injection vulnerability exists in the gradio-app/gradio repository, specifically within the 'test-functional.yml' workflow. The vulnerability arises due to improper neutralization of specialPYSEC-2025-118 Gradio is an open-source Python package that allows quick building of demos and web application for machine learning models, API, or any arbitrary Python function. Gradio's Access Control List (ACL) fPYSEC-2026-345 Gradio allows users to access arbitrary filesPYSEC-2023-300 Deserialization of Untrusted Data in GitHub repository huggingface/transformers prior to 4.36.PYSEC-2026-2290 A vulnerability in the LightGlue model loading path of huggingface/transformers version 5.2.0 allows an attacker-controlled model repository to execute arbitrary code during model initialization. The PYSEC-2026-2446 Diffusers: TOCTOU Trust Remote Code BypassPYSEC-2026-40 Diffusers is the a library for pretrained diffusion models. Prior to 0.38.0, a trust_remote_code bypass in DiffusionPipeline.from_pretrained allows arbitrary remote code execution despite the user paPYSEC-2026-41 Diffusers is the a library for pretrained diffusion models. Prior to 0.38.0, diffusers 0.37.0 allows remote code execution without the trust_remote_code=True safeguard when loading pipelines from HugPYSEC-2023-249 Gradio is an open-source Python package that allows you to quickly build a demo or web application for your machine learning model, API, or any arbitary Python function. Versions of `gradio` prior to PYSEC-2024-184 A local file inclusion vulnerability exists in the JSON component of gradio-app/gradio version 4.25. The vulnerability arises from improper input validation in the `postprocess()` function within `graPYSEC-2024-196 Gradio is an open-source Python package designed for quick prototyping. This vulnerability is related to **CORS origin validation**, where the Gradio server fails to validate the request origin when aPYSEC-2024-197 Gradio is an open-source Python package designed for quick prototyping. This vulnerability involves a **one-level read path traversal** in the `/custom_component` endpoint. Attackers can exploit this PYSEC-2024-198 Gradio is an open-source Python package designed for quick prototyping. This vulnerability involves data exposure due to the enable_monitoring flag not properly disabling monitoring when set to False.PYSEC-2024-199 Gradio is an open-source Python package designed for quick prototyping. This vulnerability involves a **timing attack** in the way Gradio compares hashes for the `analytics_dashboard` function. Since PYSEC-2024-213 Gradio is an open-source Python package designed for quick prototyping. This vulnerability relates to the **bypass of directory traversal checks** within the `is_in_or_equal` function. This function, PYSEC-2024-214 Gradio is an open-source Python package designed for quick prototyping. This vulnerability relates to **CORS origin validation accepting a null origin**. When a Gradio server is deployed locally, the PYSEC-2024-216 Gradio is an open-source Python package designed for quick prototyping. This vulnerability is a **lack of integrity check** on the downloaded FRP client, which could potentially allow attackers to intPYSEC-2024-217 Gradio is an open-source Python package designed for quick prototyping. This is a **data validation vulnerability** affecting several Gradio components, which allows arbitrary file leaks through the pPYSEC-2024-218 Gradio is an open-source Python package designed for quick prototyping. This vulnerability involves a **race condition** in the `update_root_in_config` function, allowing an attacker to modify the `roPYSEC-2024-220 Gradio is an open-source Python package designed for quick prototyping. This vulnerability involves **Cross-Site Scripting (XSS)** on any Gradio server that allows file uploads. Authenticated users caPYSEC-2024-255 Gradio before 4.20 allows credential leakage on Windows.Code that can be exploited: injection, hardcoded credentials and similar.
Nothing found by this check. ✓
Packages that look intentionally malicious: typosquats, sneaky install scripts.
This check didn’t finish — that’s not the same as “clean.” Try Check again above.
A signal about how the project is maintained — not a vulnerability in your code. It doesn’t affect the verdict above.
Maintenance & supply-chain hygiene. A signal about the project, not a vulnerability in your code.
This check didn’t finish — that’s not the same as “clean.” Try Check again above.