
CVE-2026-27167: Critical Credential Leakage and Open Redirect in Gradio OAuth Flow A critical vulnerability in the Gradio Python package allows unauthenticated remote attackers to extract sensitive Hugging Face access tokens from the server environmen... https://cvereports.com/reports/CVE-2026-27167
Post summary
The report announces a critical credential leakage and open redirect vulnerability in Gradio’s OAuth flow, allowing unauthenticated attackers to retrieve Hugging Face access tokens from the server environment.


