Gradio is an open-source Python package designed for quick prototyping. Prior to version 6.6.0, the redirectto_target() function in Gradio's OAuth flow accepts an unvalidated targeturl query parameter, allowing redirection to arbitrary external URLs. This affects the /logout and /login/callback endpoints on Gradio apps with OAuth enabled (i.e. apps running on Hugging Face Spaces with gr.LoginButton). Starting in version 6.6.0, the targeturl parameter is sanitized to only use the path, query, and fragment, stripping any scheme or host.