{"id":"CVE-2024-0964","aliases":["GHSA-f3h9-8phc-6gvh","PYSEC-2024-261"],"url":"https://o3.security/vulnerability/CVE-2024-0964","summary":"LFI in Gradio","details":"A local file include could be remotely triggered in Gradio due to a vulnerable user-supplied JSON value in an API request.","published":"2024-02-05T22:53:44.859Z","modified":"2026-07-15T01:49:02.040723700Z","cvss":{"score":7.5,"severity":"HIGH","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"},"epss":null,"cisaKev":null,"exploitsKnown":1,"affectedPackages":[{"ecosystem":"PyPI","name":"gradio","fixedVersion":"4.9.0"}],"fix":{"url":"https://github.com/gradio-app/gradio/commit/d76bcaaaf0734aaf49a680f94ea9d4d22a602e70","label":"gradio-app/gradio@d76bcaa"},"references":[{"type":"WEB","url":"https://huntr.com/bounties/25e25501-5918-429c-8541-88832dfd3741"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/0xxx/CVE-2024-0964.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-0964"},{"type":"FIX","url":"https://github.com/gradio-app/gradio/commit/d76bcaaaf0734aaf49a680f94ea9d4d22a602e70"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-07-15T01:49:02.040723700Z"}}