CVE-2024-1728
CVSS v3
7.5
HIGH
EPSS Score
85.4 %
exploit probability, as of 2026-10-05
CISA KEV
No
known exploited
Exploitation
—
SSVC status
Description
gradio-app/gradio is vulnerable to a local file inclusion vulnerability due to improper validation of user-supplied input in the UploadButton component. Attackers can exploit this vulnerability to read arbitrary files on the filesystem, such as private SSH keys, by manipulating the file path in the request to the `/queue/join` endpoint. This issue could potentially lead to remote code execution. The vulnerability is present in the handling of file upload paths, allowing attackers to redirect file uploads to unintended locations on the server.
Technical details
- Published
- 2024-04-10
Frequently asked questions
What is CVE-2024-1728?
gradio-app/gradio is vulnerable to a local file inclusion vulnerability due to improper validation of user-supplied input in the UploadButton component. Attackers can exploit this vulnerability to read arbitrary files on the filesystem, such as private SSH keys, by manipulating the file path in the request to the `/queue/join` endpoint. This issue could potentially lead to remote code execution. The vulnerability is present in the handling of file upload paths, allowing attackers to redirect file uploads to unintended locations on the server.
Is CVE-2024-1728 actively exploited?
Active exploitation of CVE-2024-1728 has not been confirmed. Its EPSS score was 85.4% on 2026-10-05, the estimated probability of exploitation in the next 30 days.
What is the CVSS score for CVE-2024-1728?
CVE-2024-1728 has a CVSS v3 base score of 7.5 (HIGH severity).
Is CVE-2024-1728 affecting your environment?
Use isMalicious to check if any of your IPs or domains are associated with this vulnerability's IOCs.
No credit card required · 50 free checks/month · Free API key
Other 2024 vulnerabilities worth triaging
Ranked by exploit probability (EPSS).