AETERNAE AI RESEARCH LLC INDEPENDENT RESEARCH
ÆAETERNAERESEARCH
Sign inRequest access
← CVE index
Δ / VULNERABILITY RECORD

CVE-2026-49119.

Source-reported disclosure and enrichment record.

SEVERITY / CVSSHIGH / 8.7CVSS 4.0 · GitHub reviewed advisory
EXPLOITATION STATUSNot listed in the cached KEV catalogThis does not establish absence of exploitation.
RECORD STATUSGitHub reviewed advisoryModified Oct 02, 2026

Disclosure summary

Gradio before 6.16.0 contain a path traversal vulnerability in the FileExplorer component's preprocess() method that allows unauthenticated attackers to escape the configured root directory by supplying path segments containing directory traversal sequences or absolute paths. Attackers can provide crafted path segments that cause os.path.join to discard the root_dir prefix entirely, resulting in arbitrary file read or exposure of sensitive files outside the intended directory.

Source-specific records & product guidance

Sources retain their own attribution and scoring. Follow the original record to confirm affected versions, fixed releases, and configuration conditions.

GitHub Reviewed Security Advisories · GHSA-j36p-7w88-g82j

Open original source · Updated Oct 02, 2026

Gradio FileExplorer preprocess path traversal allows files outside root_dir to reach callbacks

Source severity: HIGH / 8.7

EcosystemPackageAffected rangeFirst patched
pipgradio< 6.16.06.16.0

Original records & references

PUBLISHED 2026-07-01T17:36:18-04:00
MODIFIED 2026-10-02T14:29:49-04:00
INGESTED 2026-10-06T11:45:17-04:00