Ad

CVE-2026-28415

MEDIUM CVSS 3.1: 4.3 EPSS 0.01%
Updated Feb 27, 2026
Python
Parameter Value
CVSS 4.3 (MEDIUM)
Type CWE-200 (Information Exposure), CWE-330, CWE-601 (Open Redirect), CWE-284 (Improper Access Control)
Vendor Python
Public PoC No

Gradio is an open-source Python package designed for quick prototyping. Prior to version 6.6.0, the _redirect_to_target() function in Gradio's OAuth flow accepts an unvalidated _target_url query parameter, allowing redirection to arbitrary external URLs. This affects the /logout and /login/callback endpoints on Gradio apps with OAuth enabled (i.e. apps running on Hugging Face Spaces with gr.LoginButton).

Starting in version 6.6.0, the _target_url parameter is sanitized to only use the path, query, and fragment, stripping any scheme or host.

Attack Parameters

Attack Vector
Network
Can be exploited remotely
Attack Complexity
Low
Easy to exploit
Privileges Required
None
No privileges needed
User Interaction
Required
User action required

Impact Assessment

Confidentiality
None
No data leak
Integrity
Low
Partial data modification
Availability
None
No disruption

CVSS Vector v3.1