Skip to main content

Threat Intelligence Database

Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Package: pkg:pypi/nicegui

Threat Intelligence

Click on any threat for detailed analysis and mitigation recommendations

NiceGUI is a Python-based UI framework. Prior to version 3.12.0, two FastAPI routes that serve per-component static assets in NiceGUI accept a sub-path parameter that may resolve to a directory rather than a file. Requests that resolve to a directory raise an unhandled RuntimeError inside Starlette's FileResponse, which Uvicorn writes to the server log as a full traceback. Because the routes are reachable without authentication, a remote attacker can amplify log volume and consume disk and log-pipeline capacity on any publicly reachable NiceGUI server. This issue has been patched in version 3.12.0.

Join the discussion

NiceGUI is a Python-based UI framework. Prior to version 3.12.0, ui.restructured_text() renders reStructuredText server-side with Docutils without disabling file insertion directives. When a NiceGUI application passes attacker-controlled content to ui.restructured_text(), an attacker can use standard Docutils directives (include, csv-table with :file:, raw with :file:) to read local files readable by the NiceGUI server process. Applications that only pass trusted static strings to ui.restructured_text() are not affected. This issue has been patched in version 3.12.0.

Join the discussion

CVE-2026-39844 is a path traversal vulnerability in the Python-based UI framework NiceGUI versions prior to 3.10.0. The issue arises because PurePosixPath only recognizes forward slashes as path separators, allowing an attacker on Windows to bypass sanitization by using backslashes in upload filenames. This can lead to arbitrary file write on Windows systems when applications construct file paths using file.name, a pattern shown in NiceGUI's examples. The vulnerability has a medium severity with a CVSS score of 5.9 and is fixed in version 3.10.0.

Join the discussion

CVE-2026-33332 is a medium-severity vulnerability in the Python-based UI framework NiceGUI versions prior to 3.9.0. It involves improper input validation of a user-controlled query parameter in the app.add_media_file() and app.add_media_files() routes. This parameter affects how files are read during streaming, allowing attackers to bypass chunked streaming and force the server to load entire media files into memory simultaneously. Exploiting this can cause excessive memory consumption, degraded performance, or denial of service, especially with large files and concurrent requests. No authentication or user interaction is required to exploit this vulnerability. The issue has been patched in NiceGUI version 3.

Join the discussion

NiceGUI is a Python-based UI framework. Prior to version 3.8.0, several NiceGUI APIs that execute methods on client-side elements (`Element.run_method()`, `AgGrid.run_grid_method()`, `EChart.run_chart_method()`, and others) use an `eval()` fallback in the JavaScript-side `runMethod()` function. When user-controlled input is passed as the method name, an attacker can inject arbitrary JavaScript that executes in the victim's browser. Additionally, `Element.run_method()` and `Element.get_computed_prop()` used string interpolation instead of `json.dumps()` for the method/property name, allowing quote injection to break out of the intended string context. Version 3.8.0 contains a fix.

Join the discussion

NiceGUI is a Python-based UI framework. The ui.markdown() component uses the markdown2 library to convert markdown content to HTML, which is then rendered via innerHTML. By default, markdown2 allows raw HTML to pass through unchanged. This means that if an application renders user-controlled content through ui.markdown(), an attacker can inject malicious HTML containing JavaScript event handlers. Unlike other NiceGUI components that render HTML (ui.html(), ui.chat_message(), ui.interactive_image()), the ui.markdown() component does not provide or require a sanitize parameter, leaving applications vulnerable to XSS attacks. This vulnerability is fixed in 3.7.0.

Join the discussion

NiceGUI is a Python-based UI framework. Prior to 3.7.0, NiceGUI's FileUpload.name property exposes client-supplied filename metadata without sanitization, enabling path traversal when developers use the pattern UPLOAD_DIR / file.name. Malicious filenames containing ../ sequences allow attackers to write files outside intended directories, with potential for remote code execution through application file overwrites in vulnerable deployment patterns. This design creates a prevalent security footgun affecting applications following common community patterns. Note: Exploitation requires application code incorporating file.name into filesystem paths without sanitization. Applications using fixed paths, generated filenames, or explicit sanitization are not affected. This vulnerability is fixed in 3.7.0.

Join the discussion

CVE-2026-21874 is a medium-severity vulnerability in the NiceGUI Python UI framework versions 2.10.0 through 3.4.1. It allows unauthenticated attackers to exhaust Redis connections by repeatedly opening and closing browser tabs on applications using Redis-backed storage. The vulnerability arises because Redis connections are not properly released, leading to service degradation when the Redis connection limit is reached. Although the NiceGUI app remains operational, storage functionality breaks and errors are logged. This issue does not impact confidentiality or integrity but affects availability. The vulnerability has been patched in version 3.

Join the discussion

CVE-2026-21873 is a high-severity cross-site scripting (XSS) vulnerability in the Python UI framework NiceGUI versions 2.22.0 through 3.4.1. The flaw arises from unsafe handling of the URL fragment identifier in the pushstate event listener used by ui.sub_pages, allowing attackers to manipulate the URL fragment via cross-site iframes without requiring user interaction or privileges. This can lead to partial compromise of confidentiality and integrity by injecting malicious scripts. The vulnerability has been patched in version 3.5.

Join the discussion

CVE-2026-21872 is a cross-site scripting (XSS) vulnerability in the Python-based UI framework NiceGUI versions 2.22.0 through 3.4.1. The flaw arises from unsafe handling of click event listeners in ui.sub_pages combined with attacker-controlled link rendering, allowing an attacker to execute arbitrary scripts when a user clicks a malicious link. This vulnerability requires user interaction but does not require authentication. It impacts confidentiality and integrity but not availability. The issue has been patched in version 3.

Join the discussion

Showing 1 to 10 of 14 results

Filters:Package: pkg:pypi/nicegui
Page 1 of 2
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses