YoungjaeDev Claude commited on
Commit
2980d63
·
1 Parent(s): b95781b

security: Gradio 버전 업그레이드 (4.44.0 -> 5.50.0)

Browse files

보안 취약점 패치:
- GHSA-576c-3j53-r9jj (SSRF)
- GHSA-prpg-p95c-32fv (Windows path-traversal)
- GHSA-gvv6-33j7-884g (file-upload XSS)
- GHSA-pgfv-gvc5-prfg (audio component path-traversal)
- GHSA-7xmc-vhjp-qv5q (DataFrame zip-bomb DoS)
- CVE-2024-47869 (timing attack)

🤖 Generated with [Claude Code](https://claude.com/claude-code)

Co-Authored-By: Claude <noreply@anthropic.com>

Files changed (2) hide show
  1. README.md +1 -1
  2. requirements.txt +1 -1
README.md CHANGED
@@ -4,7 +4,7 @@ emoji: "!"
4
  colorFrom: blue
5
  colorTo: red
6
  sdk: gradio
7
- sdk_version: "4.44.0"
8
  app_file: app.py
9
  pinned: false
10
  license: mit
 
4
  colorFrom: blue
5
  colorTo: red
6
  sdk: gradio
7
+ sdk_version: "5.50.0"
8
  app_file: app.py
9
  pinned: false
10
  license: mit
requirements.txt CHANGED
@@ -9,7 +9,7 @@ torchvision>=0.15.0
9
  ultralytics>=8.0.0
10
 
11
  # Web UI
12
- gradio==4.44.0 # HF Spaces sdk_version과 일치
13
  plotly>=5.0.0
14
 
15
  # Computer Vision
 
9
  ultralytics>=8.0.0
10
 
11
  # Web UI
12
+ gradio>=5.50.0 # 보안 취약점 패치 (CVE-2024 SSRF, XSS, path traversal 등)
13
  plotly>=5.0.0
14
 
15
  # Computer Vision