CVE-2024-47871·Python vulnerability
Gradio is an open-source Python package designed for quick prototyping. This vulnerability involves **insecure communication** between the FRP (Fast Reverse Proxy) client and server when Gradio's `share=True` option is used. HTTPS is not enforced on the connection, allowing attackers to intercept and read files uploaded to the Gradio server, as well as modify responses or data sent between the client and server. This impacts users who are sharing Gradio demos publicly over the internet using `share=True` without proper encryption, exposing sensitive data to potential eavesdroppers. Users are advised to upgrade to `gradio>=5` to address this issue. As a workaround, users can avoid using `share=True` in production environments and instead host their Gradio applications on servers with HTTPS enabled to ensure secure communication.
- Severity
- critical
- Software
- Python
- Fixed in
- 5.0.0
- Published
- 2024-10-10
Affected versions
Until: 5.0.0
Fixed in: 5.0.0
How to fix this CVE
Upgrade Gradio to version 5.0.0 or later to enforce HTTPS encryption on FRP client-server communication. If you are currently using Gradio's `share=True` feature in production, immediately disable it and migrate to a self-hosted Gradio instance with proper TLS/SSL certificates. Users on older versions should patch as soon as possible to prevent unencrypted data transmission.
sudo dnf update python3 && pip3 install --upgrade gradio>=5.0.0Defensia detects this vulnerability
How to check if you are affected
- Check installed Gradio version: pip3 show gradio | grep Version
- Verify if Gradio is actively used with share=True: grep -r 'share=True' /path/to/gradio/apps/ --include='*.py'
- Monitor network traffic for unencrypted FRP connections: tcpdump -i any 'tcp port 7860' -A | grep -i 'frp\|gradio'
- Confirm patch installation: pip3 show gradio | grep Version (should show 5.0.0 or higher)
FAQ
What is CVE-2024-47871?
CVE-2024-47871 is a critical vulnerability in Gradio where the FRP reverse proxy connection used by the `share=True` feature operates without HTTPS encryption, allowing attackers on the network path to intercept uploaded files and modify server responses.
Is CVE-2024-47871 being actively exploited?
No, CVE-2024-47871 is not currently listed on the CISA Known Exploited Vulnerabilities (KEV) catalog and no public exploits have been released, but the critical CVSS score warrants immediate patching.
What versions of Gradio are affected by CVE-2024-47871?
All versions of Gradio prior to 5.0.0 are vulnerable when the `share=True` option is enabled. Version 5.0.0 and later enforce HTTPS on FRP communications.
How do I check if my server is vulnerable to CVE-2024-47871?
Run `pip3 show gradio` to check the version number. If it is below 5.0.0 and you have `share=True` configured in any Gradio application, your deployment is vulnerable.
Does Defensia detect CVE-2024-47871?
Yes — Defensia's CVE advisory scanner compares installed package versions against the NVD database. If Gradio is installed on a monitored server and is below version 5.0.0, CVE-2024-47871 will appear in your dashboard with remediation steps.
Related Python CVEs
References
Track CVEs across your fleet automatically
Defensia scans your Linux servers and tells you exactly which ones are running vulnerable versions — including CVE-2024-47871. Free for 1 server.
Get started free