CVE-2023-6572: False positive
(updated )
This advisory has been marked as a False Positive and has been removed. CVE-2023-6572 is a GitHub Actions expression injection vulnerability in the gradio project’s CI workflow file (.github/workflows/generate-changeset.yml). It affects the project’s CI/CD infrastructure only, not the gradio library distributed via PyPI. The fix commit (5b5af18) removes an unquoted echo expression from a workflow file and has no impact on any released version of the gradio package.
References
Code Behaviors & Features
Detect and mitigate CVE-2023-6572 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →