Executive brief
Gradio is a popular Python library used to build web interfaces for machine learning models. A security flaw in its login system allows unauthorized users to steal the server owner's Hugging Face credentials if the application is hosted outside of the Hugging Face platform. This could lead to an attacker gaining full access to the developer's private AI models and data.
Technical details
Gradio applications using OAuth components (like gr.LoginButton) outside of Hugging Face Spaces automatically enable 'mocked' OAuth routes. The component retrieves the server's own Hugging Face access token via huggingface_hub.get_token() and injects it into the session cookie of any visitor who accesses the /login/callback endpoint. Furthermore, the session cookie is signed using a hardcoded secret derived from a constant string ('-v4') when OAUTH_CLIENT_SECRET is not set. An attacker can trigger the OAuth flow, receive the session cookie, and decode it to extract the server's plaintext access token. This issue is fixed in version 6.6.0.
Affected products
- gradio-app gradio >= 4.16.0, < 6.6.0
Timeline
- 2026-02-27: disclosed
- 2026-02-27: patched: Fixed in version 6.6.0
- 2026-03-01: advisory
References
- https://api.github.com/users/tenbbughunters
- https://github.com/tenbbughunters
- https://api.github.com/users/tenbbughunters/gists%7B/gist_id%7D
- https://api.github.com/users/tenbbughunters/repos
- https://avatars.githubusercontent.com/u/152317477?v=4
- https://api.github.com/users/tenbbughunters/events%7B/privacy%7D