gradio is vulnerable to Session Fixation
60
Medium Risk
In affected versions, the /proxy= reverse proxy reused a shared httpx.AsyncClient across requests, causing cookies set by one proxied *.hf.space instance to be stored and replayed to other *.hf.space targets. A malicious Space could abuse this behavior by setting attacker-controlled cookies scoped to the parent hf.space domain, leading to cross-Space session fixation and unintended session sharing between proxied applications.
You are affected if you are using a version that falls within the vulnerable range.
gradio is vulnerable to Session Fixation in versions 3.18.0 - 6.14.0.
Upgrade the gradio library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant