CVE-2026-27167 | gradio-app gradio up to 6.5.x OAuth /login/huggingface get_token hard-coded credentials (GHSA-h3h8-3v2v-rg7m / EUVD-2026-9075)
A vulnerability has been found in gradio-app gradio up to 6.5.x and classified as critical. Affected by this issue is the function get_token of the file /login/huggingface of the component OAuth Component. The manipulation leads to hard-coded credentials.
This vulnerability is traded as CVE-2026-27167. It is possible to initiate the attack remotely. There is no exploit available.
The affected component should be upgraded.