Command Injection in GitHub repository gradio-app/gradio prior to main.
The product constructs all or part of a command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended command when it is sent to a downstream component.
Link | Tags |
---|---|
https://huntr.com/bounties/21d2ff0c-d43a-4afd-bb4d-049ee8da5b5c | issue tracking third party advisory exploit patch |
https://github.com/gradio-app/gradio/commit/5b5af1899dd98d63e1f9b48a93601c2db1f56520 | patch |