CVE-2026-27167
Last modified
CVE-2026-27167 is a medium-severity vulnerability rated 5.9/10 on the CVSS scale. Gradio is an open-source Python package designed for quick prototyping. Starting in version 4.16.0 and prior to version 6.6.0, Gradio applications running outside of Hugging Face Spaces automatically enable "mocked" OAuth routes when OAuth components (e.g. EPSS estimates a 0.45% chance of exploitation in the next 30 days.
Description
Gradio is an open-source Python package designed for quick prototyping. Starting in version 4.16.0 and prior to version 6.6.0, Gradio applications running outside of Hugging Face Spaces automatically enable "mocked" OAuth routes when OAuth components (e.g. `gr.LoginButton`) are used. When a user visits `/login/huggingface`, the server retrieves its own Hugging Face access token via `huggingface_hub.get_token()` and stores it in the visitor's session cookie. If the application is network-accessible, any remote attacker can trigger this flow to steal the server owner's HF token. The session cookie is signed with a hardcoded secret derived from the string `"-v4"`, making the payload trivially decodable. Version 6.6.0 fixes the issue.
Metrics
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Gradio Project | Gradio | >= 4.16.0, < 6.6.0 |
References
- https://github.com/gradio-app/gradio/security/advisories/GHSA-h3h8-3v2v-rg7mExploit, Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2026-27167?
How severe is CVE-2026-27167?
How do I fix CVE-2026-27167?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-27156NiceGUI is a Python-based UI framework. Prior to version 3.8…6.1
- CVE-2026-2716The Client Testimonial Slider plugin for WordPress is vulner…4.4
- CVE-2026-27161GetSimple CMS is a content management system. All versions o…7.5
- CVE-2026-27162Discourse is an open source discussion platform. Prior to ve…4.9
- CVE-2026-27163Rejected reason: This CVE was assigned in error.
- CVE-2026-27166Discourse is an open source discussion platform. Prior to ve…5.4
- CVE-2026-27168SAIL is a cross-platform library for loading and saving imag…9.8
- CVE-2026-27169OpenSift is an AI study tool that sifts through large datase…8.9
- CVE-2026-2717The HTTP Headers plugin for WordPress is vulnerable to CRLF …5.5
- CVE-2026-27170OpenSift is an AI study tool that sifts through large datase…7.1
- CVE-2026-27171zlib before 1.3.2 allows CPU consumption via crc32_combine64…5.5
- CVE-2026-27172The ConsulRegistry in the camel-consul component (class org.…8.8
Are you affected by CVE-2026-27167?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
