PT-2026-44008 · Gradio · Gradio
CVSS v4.0
7.6
High
| Vector | AV:N/AC:H/AT:N/PR:N/UI:P/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
Gradio versions prior to 6.15.0
Description
A cookie injection issue exists due to a shared module-level HTTP client used across all users in the reverse proxy endpoint. This allows remote attackers who control any HF Space to return a parent-domain cookie. The shared client stores this cookie and automatically replays it into subsequent proxy requests to other legitimate Spaces, enabling cross-Space session fixation for all users of the same Gradio deployment.
Recommendations
Update to version 6.15.0 or later.
Exploit
Fix
Session Fixation
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Gradio