Medium severity6.8NVD Advisory· Published May 27, 2026· Updated Jul 14, 2026
CVE-2026-48545
CVE-2026-48545
Description
Gradio before version 6.15.0 contains a cookie injection vulnerability that allows remote attackers to perform cross-Space session fixation by exploiting a shared module-level HTTP client used across all users in the reverse proxy endpoint. Attackers controlling any HF Space can return a parent-domain cookie that the shared client stores and automatically replays into all subsequent proxy requests to other legitimate Spaces, affecting all users of the same Gradio deployment.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
gradioPyPI | < 6.15.0 | 6.15.0 |
Affected products
3(expand)+ 1 more
- (no CPE)
- (no CPE)range: <6.15.0
Patches
Vulnerability mechanics
References
8- github.com/gradio-app/gradio/commit/feb7237d01f359d2ad4ee42d00344e61692b3b39nvdPatchWEB
- github.com/gradio-app/gradio/pull/13384nvdIssue TrackingPatchWEB
- github.com/advisories/GHSA-7hp7-4p35-3cx2ghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2026-48545ghsaADVISORY
- github.com/gradio-app/gradio/issues/13369nvdIssue TrackingWEB
- github.com/gradio-app/gradio/releases/tag/gradio%406.15.0nvdProductRelease Notes
- github.com/gradio-app/gradio/releases/tag/[email protected]ghsaWEB
- www.vulncheck.com/advisories/gradio-cookie-injection-via-shared-pronvdBroken LinkWEB
News mentions
0No linked articles in our index yet.