CVE-2024-1540
Command Injection in gradio-app/gradio via deploy+test-visual.yml workflow
- 公開済み
- 2024/03/27
- 更新済み
- 2024/08/21
- CNA の割り当て
- @huntr_ai
- 観察された証拠
- 2026/09/01
プライマリ CVSS
nvd · CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N低 · 今後 30 日間
- パーセンタイル
- 79.4%
- モデルの日付
- 2026/09/21
EPSS は統計的な推定値であり、確実性や影響の尺度ではありません。 CVSS、KEV ステータス、暴露、環境と組み合わせます。
概要
A command injection vulnerability exists in the deploy+test-visual.yml workflow of the gradio-app/gradio repository, due to improper neutralization of special elements used in a command. This vulnerability allows attackers to execute unauthorized commands, potentially leading to unauthorized modification of the base repository or secrets exfiltration. The issue arises from the unsafe handling of GitHub context information within a `run` operation, where expressions inside `${{ }}` are evaluated and substituted before script execution. Remediation involves setting untrusted input values to intermediate environment variables to prevent direct influence on script generation.
ソース
制御されたセキュリティ研究ラボで、CVE-2024-1540(gradio-app/gradio の deploy+test-visual.yml における GitHub Actions コマンドインジェクション)を再現 — gradio-app/gradio @ f35f615e33a5dd90bfeb106b6f5dca689849fcef のフラット化スナップショット
責任ある使用
脆弱性情報は、自分が所有しているシステム、またはテストを許可されているシステムでのみ使用してください。 Kitploit は公開研究メタデータにリンクしており、エクスプロイト コードや悪意のあるペイロードは保存しません。