PT-2025-50275 · Nicegui · Nicegui

Y4Rvin

·

Published

2025-12-09

·

Updated

2025-12-10

·

CVE-2025-66645

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions NiceGUI versions 3.3.1 and below
Description NiceGUI, a Python-based UI framework, contains a flaw that allows a remote attacker to read arbitrary files on the server filesystem. This is due to a directory traversal issue present in the App.add media files() function. The App.add media files() function does not properly sanitize file paths, allowing an attacker to potentially access sensitive information.
Recommendations Update to version 3.4.0 or later.

Exploit

Fix

Path traversal

Weakness Enumeration

Related Identifiers

CVE-2025-66645
GHSA-HXP3-63HC-5366

Affected Products

Nicegui