An open redirect vulnerability exists in the latest version of gradio-app/gradio. The vulnerability allows an attacker to redirect users to a malicious website by URL encoding. This can be exploited by sending a crafted request to the application, which results in a 302 redirect to an attacker-controlled site.
                
            References
                    | Link | Resource | 
|---|---|
| https://huntr.com/bounties/adc23067-ec04-47ef-9265-afd452071888 | Exploit Third Party Advisory | 
| https://huntr.com/bounties/adc23067-ec04-47ef-9265-afd452071888 | Exploit Third Party Advisory | 
Configurations
                    History
                    26 Mar 2025, 16:39
| Type | Values Removed | Values Added | 
|---|---|---|
| References | () https://huntr.com/bounties/adc23067-ec04-47ef-9265-afd452071888 - Exploit, Third Party Advisory | |
| Summary | 
 | |
| CPE | cpe:2.3:a:gradio_project:gradio:-:*:*:*:*:python:*:* | |
| CVSS | v2 : v3 : | v2 : unknown v3 : 6.1 | 
| First Time | Gradio Project Gradio Project gradio | 
20 Mar 2025, 14:15
| Type | Values Removed | Values Added | 
|---|---|---|
| References | () https://huntr.com/bounties/adc23067-ec04-47ef-9265-afd452071888 - | 
20 Mar 2025, 10:15
| Type | Values Removed | Values Added | 
|---|---|---|
| New CVE | 
Information
                Published : 2025-03-20 10:15
Updated : 2025-03-26 16:39
NVD link : CVE-2024-8021
Mitre link : CVE-2024-8021
CVE.ORG link : CVE-2024-8021
JSON object : View
Products Affected
                gradio_project
- gradio
CWE
                
                    
                        
                        CWE-601
                        
            URL Redirection to Untrusted Site ('Open Redirect')
