CVE-2024-4254
The 'deploy-website.yml' workflow in the gradio-app/gradio repository, specifically in the 'main' branch, is vulnerable to secrets exfiltration due to improper authorization. The vulnerability arises from the workflow's explicit checkout and execution of code from a fork, which is unsafe as it allows the running of untrusted code in an environment with access to push to the base repository and access secrets. This flaw could lead to the exfiltration of sensitive secrets such as GITHUB_TOKEN, HF_TOKEN, VERCEL_ORG_ID, VERCEL_PROJECT_ID, COMMENT_TOKEN, AWSACCESSKEYID, AWSSECRETKEY, and VERCEL_TOKEN. The vulnerability is present in the workflow file located at https://github.com/gradio-app/gradio/blob/72f4ca88ab569aae47941b3fb0609e57f2e13a27/.github/workflows/deploy-website.yml.
Scoring
- Severity
- HIGH
- CVSS base score
- 7.1
- CVSS vector
- CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:L/A:N
- EPSS probability
- 0.47%
- CWE
- CWE-214
- Published
- 2024-06-04
- Last modified
- 2026-03-13
Affected products
- gradio-app gradio-app/gradio
Weakness type
Related vulnerabilities
- CVE-2026-81684 — openssl_encrypt before 1.4.9 Information Disclosure via Command Line
- CVE-2026-80158 — Ansible-collection-community-general: community.general: ipa_getkeytab does not set no_log on the bind_pw parameter, disclosing the ipa bind password in logs and process listings
- CVE-2026-65088 — NVIDIA NemoClaw contains a vulnerability where an attacker could cause...
- CVE-2026-76054 — Invocation of Process Using Visible Sensitive Information in Black Duck blackduck-c-cpp 1.0.17...
- CVE-2026-74873 — openssl_encrypt before 1.4.0 Password Exposure via CLI Argument
- CVE-2026-18915 — Exposure of OTP Secret Through Process Command-Line Arguments in TÜBİTAK BİLGEM's eta-otp-lock
- CVE-2026-12139 — Tanium addressed an information disclosure vulnerability in Connect.
- CVE-2026-9494 — ubuntu-pro-client Information Disclosure via Cleartext Bearer Token Exposure in Process Command Line