Executive brief
Gradio, a library used to build and share machine learning web applications, contains a flaw in its login and logout process. An attacker can create a specially crafted link that, when clicked by a user, redirects them from a trusted Gradio or Hugging Face domain to a malicious website. This can be used in phishing campaigns to trick users into providing credentials or downloading malware by exploiting their trust in the original domain.
Technical details
An open redirect vulnerability exists in Gradio's OAuth implementation within the `_redirect_to_target()` function. The function retrieves a destination from the `_target_url` query parameter and passes it directly to a `RedirectResponse` without validation. This affects the `/logout` and `/login/callback` endpoints in applications where OAuth is enabled (such as those using `gr.LoginButton` on Hugging Face Spaces). An attacker can exploit this by sending a crafted URL to a victim, which will redirect them to an external malicious host after a successful login or logout action. The vulnerability is fixed in version 6.6.0 by sanitizing the parameter to only allow local paths.
Affected products
- gradio-app gradio < 6.6.0
Timeline
- 2026-02-27: disclosed
- 2026-02-27: patched: Version 6.6.0 released
- 2026-03-01: advisory