📦 Nicegui

by Zauberzeug

🔍 What is Nicegui?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2026-25732

HIGH CVSS 7.5 Feb 6, 2026

This vulnerability in NiceGUI allows attackers to perform path traversal attacks by uploading files with malicious filenames containing '../' sequences. When developers use the vulnerable pattern of c...

CVE-2026-21873

HIGH CVSS 7.2 Jan 8, 2026

This vulnerability in NiceGUI allows attackers to manipulate URL fragment identifiers via cross-site iframe attacks, potentially enabling UI manipulation or client-side attacks. It affects NiceGUI ver...

CVE-2025-66645

HIGH CVSS 7.5 Dec 9, 2025

This directory traversal vulnerability in NiceGUI allows remote attackers to read arbitrary files on the server filesystem by exploiting the App.add_media_files() function. Any application using NiceG...

CVE-2026-27156

MEDIUM CVSS 6.1 Feb 24, 2026

This vulnerability in NiceGUI allows cross-site scripting (XSS) attacks when user-controlled input is passed to certain client-side method execution APIs. Attackers can inject arbitrary JavaScript tha...

CVE-2026-25516

MEDIUM CVSS 6.1 Feb 6, 2026

This CVE describes a cross-site scripting (XSS) vulnerability in NiceGUI's ui.markdown() component. Attackers can inject malicious JavaScript through user-controlled markdown content, which gets rende...

CVE-2026-21871

MEDIUM CVSS 6.1 Jan 8, 2026

This is a cross-site scripting (XSS) vulnerability in NiceGUI Python UI framework that allows attackers to execute arbitrary JavaScript in victims' browsers when untrusted input is passed to specific ...

CVE-2026-21872

MEDIUM CVSS 6.1 Jan 8, 2026

This is a cross-site scripting (XSS) vulnerability in NiceGUI Python UI framework versions 2.22.0 through 3.4.1. Attackers can inject malicious scripts via crafted links that execute when users click ...

CVE-2026-21874

MEDIUM CVSS 5.3 Jan 8, 2026

This vulnerability allows unauthenticated attackers to exhaust Redis connections by repeatedly opening and closing browser tabs on NiceGUI applications using Redis-backed storage. Affected users are t...

CVE-2025-66470

MEDIUM CVSS 6.1 Dec 9, 2025

NiceGUI versions 3.3.1 and below contain a cross-site scripting (XSS) vulnerability in the ui.interactive_image component. Attackers can inject malicious JavaScript via SVG foreignObject tags when ren...

CVE-2025-66469

MEDIUM CVSS 6.1 Dec 9, 2025

NiceGUI versions 3.3.1 and below are vulnerable to Reflected Cross-Site Scripting (XSS) through the ui.add_css, ui.add_scss, and ui.add_sass functions. Attackers can inject malicious JavaScript by bre...