PT-2026-44008 · Gradio · Gradio

·

CVE-2026-48545

·

Published

2026-05-27

·

Updated

2026-06-02

CVSS v4.0

7.6

High

VectorAV:N/AC:H/AT:N/PR:N/UI:P/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Gradio versions prior to 6.15.0
Description A cookie injection issue exists due to a shared module-level HTTP client used across all users in the reverse proxy endpoint. This allows remote attackers who control any HF Space to return a parent-domain cookie. The shared client stores this cookie and automatically replays it into subsequent proxy requests to other legitimate Spaces, enabling cross-Space session fixation for all users of the same Gradio deployment.
Recommendations Update to version 6.15.0 or later.

Exploit

Fix

Session Fixation

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-48545
GHSA-7HP7-4P35-3CX2
PYSEC-2026-2178

Affected Products

Gradio