SCA: security update for gradio (GHSA-39mp-8hj3-5c49)

high Tenable Cloud Security Plugin ID 438053

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- Gradio is an open-source Python package designed for quick prototyping. Prior to version 6.7, Gradio apps
running on Window with Python 3.13+ are vulnerable to an absolute path traversal issue that enables
unauthenticated attackers to read arbitrary files from the file system. Python 3.13+ changed the
definition of `os.path.isabs` so that root-relative paths like `/windows/win.ini` on Windows are no longer
considered absolute paths, resulting in a vulnerability in Gradio's logic for joining paths safely. This
can be exploited by unauthenticated attackers to read arbitrary files from the Gradio server, even when
Gradio is set up with authentication. Version 6.7 fixes the issue. (CVE-2026-28414)

Solution

Update the gradio library and its related packages to version 6.7.0 or later.

See Also

https://github.com/advisories/GHSA-39mp-8hj3-5c49

Plugin Details

Severity: High

ID: 438053

Version: Revision 1.7

Type: Local

Family: SCA Checks

Published: 3/2/2026

Updated: 7/6/2026

Supported Sensors: Tenable Cloud Security, Tenable Self-Hosted Container Security

Risk Information

VPR

Risk Factor: Low

Score: 3

Percentile: 23.73

Vendor

Vendor Severity: High

CVSS v2

Risk Factor: High

Base Score: 7.8

Temporal Score: 6.1

Vector: CVSS2#AV:N/AC:L/Au:N/C:C/I:N/A:N

CVSS Score Source: CVE-2026-28414

CVSS v3

Risk Factor: High

Base Score: 7.5

Temporal Score: 6.7

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Temporal Vector: CVSS:3.0/E:P/RL:O/RC:C

Vulnerability Information

Exploit Available: true

Exploit Ease: Exploits are available

Patch Publication Date: 3/1/2026

Vulnerability Publication Date: 2/27/2026

Reference Information

CVE: CVE-2026-28414