No analysis available yet.
No remediation available yet.
Tracking
Sign in to view the affected projects.
No advisories yet.
Wed, 27 May 2026 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 27 May 2026 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Gradio before version 6.15.0 contains a cookie injection vulnerability that allows remote attackers to perform cross-Space session fixation by exploiting a shared module-level HTTP client used across all users in the reverse proxy endpoint. Attackers controlling any HF Space can return a parent-domain cookie that the shared client stores and automatically replays into all subsequent proxy requests to other legitimate Spaces, affecting all users of the same Gradio deployment. | |
| Title | Gradio < 6.15.0 Cookie Injection via Shared Proxy Client | |
| Weaknesses | CWE-384 | |
| References |
|
|
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-05-27T15:35:52.619Z
Reserved: 2026-05-21T18:34:46.417Z
Link: CVE-2026-48545
Updated: 2026-05-27T15:35:48.702Z
Status : Received
Published: 2026-05-27T15:16:31.020
Modified: 2026-05-27T15:16:31.020
Link: CVE-2026-48545
No data.
OpenCVE Enrichment
No data.