{"id":"CVE-2024-8021","aliases":["PYSEC-2026-1411"],"url":"https://o3.security/vulnerability/CVE-2024-8021","summary":"Gradio Vulnerable to Open Redirect","details":"An open redirect vulnerability exists in the latest version of gradio-app/gradio. The vulnerability allows an attacker to redirect users to a malicious website by URL encoding. This can be exploited by sending a crafted request to the application, which results in a 302 redirect to an attacker-controlled site.","published":"2025-03-20T12:32:47Z","modified":"2026-07-07T17:57:08.099550556Z","cvss":{"score":5.4,"severity":"MEDIUM","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N"},"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"PyPI","name":"gradio","fixedVersion":null}],"fix":null,"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-8021"},{"type":"PACKAGE","url":"https://github.com/gradio-app/gradio"},{"type":"WEB","url":"https://huntr.com/bounties/adc23067-ec04-47ef-9265-afd452071888"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-07-07T17:57:08.099550556Z"}}