Listen to this Post
The CVE-2025-XXXX vulnerability in Byaidu PDFMathTranslate v1.9.9 is an open redirect flaw within the `/gradio_api` endpoint. The application improperly validates and sanitizes user-supplied input in the `file` parameter. An attacker can craft a malicious URL containing this parameter with a manipulated value pointing to an external, untrusted domain. When a victim clicks the crafted link, the application’s backend processes the request and automatically redirects the user’s browser to the attacker-specified URL without sufficient validation. This occurs because the code fails to check if the redirect target is within the application’s own domain whitelist. The lack of a strict allowlist for valid redirection destinations is the core technical failure, allowing the abuse of the trusted domain name to lend credibility to the malicious link.
Platform: Python/Gradio
Version: 1.9.9
Vulnerability: Open Redirect
Severity: Low
date: 2024-10-30
Prediction: Patch 2024-11-13
What Undercode Say:
curl -I "http://localhost:7860/gradio_api?file=https://malicious.example.com"
Example of vulnerable parameter handling
@app.route('/gradio_api')
def gradio_api():
file_url = request.args.get('file')
return redirect(file_url) Unsafe redirect
How Exploit:
Attacker crafts a phishing link like `http://victim-domain.com:7860/gradio_api?file=https://evil-phishing-site.com` and sends it to users. Clicking the link redirects the user to the attacker’s fake login page, leveraging the trust in the original domain.
Protection from this CVE:
Implement strict allowlist validation for all redirect URLs, allowing only relative paths or a strict list of known-good domains. Use a central redirect function that checks the target against this allowlist.
Impact:
Phishing attacks, security filter bypass, user trust exploitation.
🎯Let’s Practice Exploiting & Learn Patching For Free:
Sources:
Reported By: github.com
Extra Source Hub:
Undercode

