Security
Headlines
HeadlinesLatestCVEs

Headline

GHSA-xcgp-r7r8-2hc9: Gradio's CI vulnerable to Command Injection

Previously, it was possible to exfiltrate secrets in Gradio’s CI, but this is now fixed.

ghsa
#git

Gradio’s CI vulnerable to Command Injection

High severity GitHub Reviewed Published Mar 27, 2024 to the GitHub Advisory Database • Updated Mar 27, 2024

ghsa: Latest News

GHSA-rm76-4mrf-v9r8: vLLM uses Python 3.12 built-in hash() which leads to predictable hash collisions in prefix cache