Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Tue, 02 Jun 2026 00:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Gradio Project
Gradio Project gradio |
|
| CPEs | cpe:2.3:a:gradio_project:gradio:*:*:*:*:*:python:*:* | |
| Vendors & Products |
Gradio Project
Gradio Project gradio |
Thu, 28 May 2026 02:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Gradio-app
Gradio-app gradio |
|
| Vendors & Products |
Gradio-app
Gradio-app gradio |
Wed, 27 May 2026 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 27 May 2026 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Gradio before version 6.15.0 contains a cookie injection vulnerability that allows remote attackers to perform cross-Space session fixation by exploiting a shared module-level HTTP client used across all users in the reverse proxy endpoint. Attackers controlling any HF Space can return a parent-domain cookie that the shared client stores and automatically replays into all subsequent proxy requests to other legitimate Spaces, affecting all users of the same Gradio deployment. | |
| Title | Gradio < 6.15.0 Cookie Injection via Shared Proxy Client | |
| Weaknesses | CWE-384 | |
| References |
|
|
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-06-23T16:16:39.281Z
Reserved: 2026-05-21T18:34:46.417Z
Link: CVE-2026-48545
Updated: 2026-05-27T15:35:48.702Z
Status : Analyzed
Published: 2026-05-27T15:16:31.020
Modified: 2026-06-17T10:55:04.547
Link: CVE-2026-48545
No data.
OpenCVE Enrichment
Updated: 2026-05-28T02:15:03Z