CVE-2026-48545
MEDIUMDescription
Gradio before version 6.15.0 contains a cookie injection vulnerability that allows remote attackers to perform cross-Space session fixation by exploiting a shared module-level HTTP client used across all users in the reverse proxy endpoint. Attackers controlling any HF Space can return a parent-domain cookie that the shared client stores and automatically replays into all subsequent proxy requests to other legitimate Spaces, affecting all users of the same Gradio deployment.
Is your site exposed to CVE-2026-48545?
Run a free security scan — no signup, results in seconds.
CVSS v3.1 Score
EPSS — Exploit Prediction
EPSS estimates the probability that this vulnerability will be exploited in the wild within the next 30 days. A higher score means more likely to be exploited.
Weakness Type (CWE)
Affected Products
| Vendor | Product |
|---|---|
| gradio_project | gradio |
References
Advisories & Patches
Frequently Asked Questions
What is CVE-2026-48545? +
How severe is CVE-2026-48545? +
What products are affected by CVE-2026-48545? +
How do I check if I'm vulnerable to CVE-2026-48545? +
Related Vulnerabilities
A Session Fixation vulnerability existed in Payload's SQLite adapter due to identifier reuse during account creation. A malicious attacker could …
A malicious actor can fix the session of a PAM user by tricking the user to click on a specially …
When configured using SAML, a session fixation vulnerability in the GlobalProtect™ login enables an attacker to impersonate a legitimate authorized …
An improper session validation allows an unauthenticated attacker to cause certain request notifications to be executed in the context of …
QuickCMS allows a user's session identifier to be set before authentication. The value of this session ID stays the same …
KTM System e-BOK allows the session identifier to be set by the client prior to authentication. If a cookie with …