CVE-2026-48545: Gradio Project Gradio
Medium severity, CVSS 6.8. EPSS: 0.5% chance of exploitation in the next 30 days.
Gradio before version 6.15.0 contains a cookie injection vulnerability that allows remote attackers to perform cross-Space session fixation by exploiting a shared module-level HTTP client used across all users in the reverse proxy endpoint. Attackers controlling any HF Space can return a parent-domain cookie that the shared client stores and automatically replays into all subsequent proxy requests to other legitimate Spaces, affecting all users of the same Gradio deployment.
Affected products
- Gradio Project Gradio: before 6.15.0 (fixed in 6.15.0)
Published 2026-05-27. Last modified 2026-10-08.