CVE-2024-12217
CVSS 3.0 Score 5.3 of 10 (medium)
Details
Published Mar 20, 2025
CWE ID 22
Summary
CVE-2024-12217 is a newly disclosed vulnerability affecting the gradio-app/gradio repository in version git 67e4044. This issue enables path traversal on Windows OS through the use of NTFS Alternate Data Streams (ADS). Despite the application's intention to restrict access to specific file paths, such as 'C:/tmp/secret.txt', it fails to block access when users employ ADS syntax, like 'C:/tmp/secret.txt::$DATA'. Consequently, unauthorized users can read files that should have been blocked, posing a potential security risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.