CVE-2026-28415 | gradio-app gradio up to 6.5.x Query Parameter /logout _redirect_to_target _target_url information disclosure (GHSA-pfjf-5gxr-995x / EUVD-2026-9083)
A vulnerability was found in gradio-app gradio up to 6.5.x. It has been declared as problematic. This issue affects the function _redirect_to_target of the file /logout of the component Query Parameter Handler. Such manipulation of the argument _target_url leads to information disclosure.
This vulnerability is uniquely identified as CVE-2026-28415. The attack can be launched remotely. No exploit exists.
It is recommended to upgrade the affected component.