CVE-2026-48545 PUBLISHED

Gradio < 6.15.0 Cookie Injection via Shared Proxy Client

Assigner: VulnCheck
Reserved: 21.05.2026 Published: 27.05.2026 Updated: 27.05.2026

Gradio before version 6.15.0 contains a cookie injection vulnerability that allows remote attackers to perform cross-Space session fixation by exploiting a shared module-level HTTP client used across all users in the reverse proxy endpoint. Attackers controlling any HF Space can return a parent-domain cookie that the shared client stores and automatically replays into all subsequent proxy requests to other legitimate Spaces, affecting all users of the same Gradio deployment.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:P/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N
CVSS Score: 7.6

Product Status

Vendor gradio-app
Product gradio
Versions Default: affected
  • affected from 0 to 6.15.0 (excl.)

Credits

  • YU SUN finder

References

Problem Types

  • Session Fixation CWE