CVE-2026-59806: Gradio-App Gradio

High severity, CVSS 7.4. EPSS: 0.4% chance of exploitation in the next 30 days.

Gradio before 6.20.0 contains an open redirect and server-side request forgery vulnerability that allows attackers to redirect users to arbitrary URLs or perform client-side SSRF by supplying unvalidated HTTP/HTTPS URLs to the file_fetch() function in the /gradio_api/file= endpoint. Attackers can craft a malicious FileData response targeting internal endpoints such as cloud metadata services to retrieve sensitive credentials including EC2 IAM role credentials.

Affected products

  • Gradio-App Gradio: before 6.20.0 (fixed in 6.20.0)

Published 2026-07-08. Last modified 2026-10-08.