Gradio v3.27.0 was discovered to contain an arbitrary file upload vulnerability via the /upload
interface.
{ "severity": "MODERATE", "cwe_ids": [ "CWE-434" ], "github_reviewed": true, "github_reviewed_at": "2023-09-21T17:12:02Z", "nvd_published_at": "2023-09-15T23:15:07Z" }