{"id":"CVE-2024-39236","details":"Gradio v4.36.1 was discovered to contain a code injection vulnerability via the component /gradio/component_meta.py. This vulnerability is triggered via a crafted input. NOTE: the supplier disputes this because the report is about a user attacking himself.","aliases":["GHSA-9v2f-6vcg-3hgv","PYSEC-2024-274"],"modified":"2026-08-12T03:51:36.651034301Z","published":"2024-07-01T00:00:00Z","database_specific":{"isDisputed":true,"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/39xxx/CVE-2024-39236.json","cna_assigner":"mitre"},"references":[{"type":"WEB","url":"https://github.com/Aaron911/PoC/blob/main/Gradio.md"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/39xxx/CVE-2024-39236.json"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-9v2f-6vcg-3hgv"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-39236"},{"type":"REPORT","url":"https://github.com/gradio-app/gradio/issues/8853"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/gradio-app/gradio","events":[{"introduced":"18a5e0e162fe12a96b8931e2e99a0973a9177393"},{"last_affected":"18a5e0e162fe12a96b8931e2e99a0973a9177393"}],"database_specific":{"cpe":"cpe:2.3:a:gradio_project:gradio:4.36.1:*:*:*:*:python:*:*","extracted_events":[{"introduced":"4.36.1"},{"last_affected":"4.36.1"}],"source":"CPE_STRING"}}],"versions":["4.36.1","website@0.31.5","gradio@4.36.1","@gradio/video@0.8.10","@gradio/uploadbutton@0.6.11","@gradio/upload@0.11.2","@gradio/simpleimage@0.5.10","@gradio/multimodaltextbox@0.4.11","@gradio/model3d@0.10.10","@gradio/lite@4.36.1","@gradio/imageeditor@0.7.10","@gradio/image@0.11.10","@gradio/gallery@0.10.10","@gradio/fileexplorer@0.4.11","@gradio/file@0.8.2","@gradio/downloadbutton@0.1.20","@gradio/dataset@0.1.43","@gradio/dataframe@0.8.10","@gradio/code@0.6.11","@gradio/client@1.1.1","@gradio/chatbot@0.10.11","@gradio/button@0.2.43","@gradio/audio@0.11.10","@gradio/app@1.36.2","@gradio/annotatedimage@0.6.10"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2024-39236.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"}]}