Session Fixation Affecting gradio package, versions [,6.15.0)


Severity

Recommended
0.0
high
0
10

CVSS assessment by Snyk's Security Team. Learn more

Threat Intelligence

Exploit Maturity
Proof of Concept
EPSS
0.04% (14th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-PYTHON-GRADIO-16960000
  • published28 May 2026
  • disclosed27 May 2026
  • creditTim Ren, AAtomical sysy

Introduced: 27 May 2026

NewCVE-2026-48545  (opens in a new tab)
CWE-384  (opens in a new tab)

How to fix?

Upgrade gradio to version 6.15.0 or higher.

Overview

gradio is a Python library for easily interacting with trained machine learning models

Affected versions of this package are vulnerable to Session Fixation via /proxy reverse proxy requests. A malicious HF Space can hijack user sessions and gain unauthorized access to other users' authenticated contexts by injecting malicious cookies through a shared HTTP client used in the reverse proxy endpoint. This allows the attacker's cookies to be replayed in subsequent proxy requests to other legitimate targets, impacting all users of the same deployment.

CVSS Base Scores

version 4.0
version 3.1