gradio is vulnerable to Session Fixation
60
Medium Risk
In affected versions, the /proxy= reverse proxy reused a shared httpx.AsyncClient across requests, causing cookies set by one proxied *.hf.space instance to be stored and replayed to other *.hf.space targets. A malicious Space could abuse this behavior by setting attacker-controlled cookies scoped to the parent hf.space domain, leading to cross-Space session fixation and unintended session sharing between proxied applications.
You are affected if you are using a version that falls within the vulnerable range.
gradio is vulnerable to Session Fixation in versions 3.18.0 - 6.14.0.
Upgrade the gradio library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant