<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-06T21:42:14.758111+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cnvd-2026-13582</id>
    <title>cnvd-2026-13582</title>
    <updated>2026-10-06T21:42:14.762841+00:00</updated>
    <content>cnvd-2026-13582</content>
    <link href="https://cve.radiocsirt.org/vuln/cnvd-2026-13582"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-273995</id>
    <title>EUVD-2026-273995</title>
    <updated>2026-10-06T21:42:14.762873+00:00</updated>
    <content>EUVD-2026-273995</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-273995"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-27167</id>
    <title>fkie_cve-2026-27167</title>
    <updated>2026-10-06T21:42:14.762886+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Gradio is an open-source Python package designed for quick prototyping. Starting in version 4.16.0 and prior to version 6.6.0, Gradio applications running outside of Hugging Face Spaces automatically enable "mocked" OAuth routes when OAuth components (e.g. `gr.LoginButton`) are used. When a user visits `/login/huggingface`, the server retrieves its own Hugging Face access token via `huggingface_hub.get_token()` and stores it in the visitor's session cookie. If the application is network-accessible, any remote attacker can trigger this flow to steal the server owner's HF token. The session cookie is signed with a hardcoded secret derived from the string `"-v4"`, making the payload trivially decodable. Version 6.6.0 fixes the issue.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-27167"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-h3h8-3v2v-rg7m</id>
    <title>GHSA-h3h8-3v2v-rg7m — Gradio: Mocked OAuth Login Exposes Server Credentials and Uses Hardcoded Session Secret</title>
    <updated>2026-10-06T21:42:14.762919+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> PyPI: gradio</p>
<p>## Summary</p>
<p>Gradio applications running outside of Hugging Face Spaces automatically enable "mocked" OAuth routes when OAuth components (e.g. `gr.LoginButton`) are used. When a user visits `/login/huggingface`, the server retrieves its own Hugging Face access token via `huggingface_hub.get_token()` and stores it in the visitor's session cookie. If the application is network-accessible, any remote attacker can trigger this flow to steal the server owner's HF token. The session cookie is signed with a hardcoded secret derived from the string `"-v4"`, making the payload trivially decodable.</p>
<p>## Affected Component</p>
<p>`gradio/oauth.py` — functions `attach_oauth()`, `_add_mocked_oauth_routes()`, and `_get_mocked_oauth_info()`.</p>
<p>## Root Cause Analysis</p>
<p>### 1. Real token injected into every visitor's session</p>
<p>When Gradio detects it is **not** running inside a Hugging Face Space (`get_space() is None`), it registers mocked OAuth routes via `_add_mocked_oauth_routes()` (line 44).</p>
<p>The function `_get_mocked_oauth_info()` (line 307) calls `huggingface_hub.get_token()` to retrieve the **real** HF access token configured on the host machine (via `HF_TOKEN` environment variable or `huggingface-cli login`). This token is stored in a dict that is then injected into the session of **any visitor** who hits `/login/callback` (line 183):</p>
<p>```python
request.session["oauth_info"] = mocked_oauth_info
```</p>
<p>The `mocked_oauth_info` dict contains the real token at key `access_token` (line 329):</p>
<p>```pytho…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-h3h8-3v2v-rg7m"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/pysec-2026-63</id>
    <title>PYSEC-2026-63</title>
    <updated>2026-10-06T21:42:14.762979+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> PyPI: gradio</p>
<p>Gradio is an open-source Python package designed for quick prototyping. Starting in version 4.16.0 and prior to version 6.6.0, Gradio applications running outside of Hugging Face Spaces automatically enable "mocked" OAuth routes when OAuth components (e.g. `gr.LoginButton`) are used. When a user visits `/login/huggingface`, the server retrieves its own Hugging Face access token via `huggingface_hub.get_token()` and stores it in the visitor's session cookie. If the application is network-accessible, any remote attacker can trigger this flow to steal the server owner's HF token. The session cookie is signed with a hardcoded secret derived from the string `"-v4"`, making the payload trivially decodable. Version 6.6.0 fixes the issue.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/pysec-2026-63"/>
  </entry>
</feed>
