Gradio < 6.20.0 - Open Redirect and SSRF via /gradio_api/file= endpoint (CVE-2026-59806) | HOL Guard CVE