PT-2025-4304 · Nicegui · Nicegui

Streamcfd

·

Published

2025-01-06

·

Updated

2025-01-06

·

CVE-2025-21618

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions NiceGUI versions prior to 2.9.1
Description The issue concerns a session management problem in NiceGUI, a Python-based UI framework. Before version 2.9.1, authenticating with NiceGUI would log the user into all browsers, including those in incognito mode. This means that once a user logged in to one browser, all other browsers would also be logged in without requiring a password, even in incognito mode. The impact of this issue is considered high.
Recommendations For versions prior to 2.9.1, update to version 2.9.1 to resolve the issue. As a temporary workaround, consider restricting access to sensitive information or using an alternative authentication method until the update can be applied.

Exploit

Fix

Improper Authentication

Weakness Enumeration

Related Identifiers

CVE-2025-21618
GHSA-V6JV-P6R8-J78W

Affected Products

Nicegui