Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:34739
HistoryMar 18, 2022 - 12:15 p.m.

Command Injection

2022-03-1812:15:42
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
14
gradio vulnerability
code injection
flagging input

EPSS

0.002

Percentile

61.7%

gradio is vulnerable to code injection. The vulnerability exists in flag and open functions in flagging.py due to lack of sanitization of flagging inputs which allows a malicious attacker to send and execute arbitrary code.

EPSS

0.002

Percentile

61.7%

Related for VERACODE:34739