CVE-2024-8021

CVSS 3.1 Score 6.1 of 10 (medium)

Details

Published Mar 20, 2025
Updated: Mar 26, 2025
CWE ID 601

Summary

CVE-2024-8021 is a newly disclosed vulnerability affecting the latest version of gradio-app/gradio. This issue involves an open redirect vulnerability, which enables attackers to manipulate URLs and redirect unsuspecting users to malicious websites. By encoding a malicious URL, an attacker can exploit this vulnerability and divert users to their controlled site, potentially exposing them to phishing or other cyber attacks. This weakness arises from the application's failure to validate and sanitize user-supplied URLs during a 302 redirect.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share