The security architecture of Gradio 5
Summary
The security overview describes changes to file paths, network access and browser boundaries in Gradio 5. Public ML demos are thereby explicitly treated as web applications with an attack surface. Gradio 5 tightens the handling of accessible files and paths.
Ideas
- Demo frameworks need secure defaults, because experiments quickly become publicly reachable.
- File sharing must define allowed paths instead of serving arbitrary local files.
Insights
- AI artefacts are active parts of the supply chain and need isolation, proof of origin and minimal privileges.
Facts
- The article discusses SSRF, XSS and access protection measures.
Critique
- Framework protection cannot completely catch insecure application code and dangerous model functions.
Recommendations
- Run public demos with minimal privileges, fixed file paths and an upstream rate limit.
References
Read the original article on Hugging Face
Links to the original source and the Web Archive open in a new tab.