PT-2026-22414 · Gradio · Gradio
Logicx24
·
Published
2026-02-27
·
Updated
2026-03-05
·
CVE-2026-28415
CVSS v3.1
4.7
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Gradio versions prior to 6.6.0
Description
Gradio is a Python package for rapid prototyping. A flaw exists in the OAuth flow where the
redirect to target() function does not properly validate the target url query parameter. This allows redirection to arbitrary external URLs via the /logout and /login/callback API endpoints when OAuth is enabled.Recommendations
Update to version 6.6.0 or later.
Exploit
Fix
Use of Insufficiently Random Values
Information Disclosure
Open Redirect
Improper Access Control
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Gradio