Security
Headlines
HeadlinesLatestCVEs

Headline

GHSA-xcgp-r7r8-2hc9: Gradio's CI vulnerable to Command Injection

Previously, it was possible to exfiltrate secrets in Gradio’s CI, but this is now fixed.

ghsa
#git

Gradio’s CI vulnerable to Command Injection

High severity GitHub Reviewed Published Mar 27, 2024 to the GitHub Advisory Database • Updated Mar 27, 2024

ghsa: Latest News

GHSA-xffm-g5w8-qvg7: @eslint/plugin-kit is vulnerable to Regular Expression Denial of Service attacks through ConfigCommentParser