CVE-2025-5320 Details
Description
A vulnerability classified as problematic has been found in gradio-app gradio up to 5.29.1. This affects the function is_valid_origin of the component CORS Handler. The manipulation of the argument localhost_aliases leads to erweiterte Rechte. It is possible to initiate the attack remotely. The complexity of an attack is rather high. The exploitability is told to be difficult. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
A vulnerability has been identified in Gradio applications, specifically in versions through 5.29.1, allowing for a bypass of Cross-Origin Resource Sharing (CORS) origin validation. This issue arises in the CORS Handler component, where the 'is_valid_origin' function improperly manages the 'localhost_aliases' argument. As a result, malicious actors can remotely exploit this vulnerability to access sensitive data from internal applications, undermining Gradio's intended protections against such cross-origin attacks.
Users are advised to update Gradio to version 5.29.2 or later, where this vulnerability has been addressed.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed May 29, 2025CISA-ADP
Assessed May 29, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://gist.github.com/superboy-zjc/aa3dfa161d7b19d8a53ab4605792f2fe | [email protected] | |
| https://gist.github.com/superboy-zjc/aa3dfa161d7b19d8a53ab4605792f2fe#proof-of-concept-poc | [email protected] | ExploitTechnical Analysis |
| https://vuldb.com/?ctiid.310491 | [email protected] | AdvisoryPermission Required |
| https://vuldb.com/?id.310491 | [email protected] | AdvisoryPermission Required |
| https://vuldb.com/?submit.580250 | [email protected] | Permission Required |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-345 | Insufficient Verification of Data Authenticity | [email protected] |
| CWE-346 | Origin Validation Error | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| gradio-app gradio | <= 5.29.1 (semver) |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jun 1, 2025 | CVE Modified | [email protected] |
| May 29, 2025 | New CVE Received | [email protected] |
Volerion