Junglewise Threat Intelligence

CVE-2026-28416: Gradio SSRF via malicious proxy_url in gr.load

CVE-2026-28416 · Severity: high · CVSS 8.2 · Published 2026-03-01

Technologies: Gradio-App Gradio. Vendors: PyPI.

Executive brief

Gradio, a popular library for building machine learning web interfaces, is vulnerable to a security flaw that allows attackers to trick a server into making unauthorized requests. By hosting a malicious 'Space' and convincing a user to load it, an attacker can gain access to sensitive internal services, private network data, or cloud credentials. This could lead to the theft of administrative keys or exposure of private internal databases.

Technical details

A Server-Side Request Forgery (SSRF) vulnerability exists in Gradio's 'gr.load()' function due to insufficient validation of the 'proxy_url' parameter in remote configuration files. When a Gradio application loads an external Space, the 'proxy_url' provided by the remote config is automatically added to an internal allowlist without verification. An attacker can provide a malicious configuration pointing to internal IP addresses or cloud metadata services (e.g., 169.254.169.254). Because Gradio's built-in '/proxy' route only performs host-based validation against this allowlist, an attacker can then use the victim's server as a reverse proxy to access restricted internal endpoints. This vulnerability is patched in version 6.6.0.

Affected products

  • gradio-app gradio < 6.6.0

Timeline

  • 2026-02-27: disclosed
  • 2026-02-27: patched: Fixed in version 6.6.0
  • 2026-03-01: advisory

References

Related threats