Vulnerabilities

ID
Packages
Summary
Published
arrow_upward
Attributes
PYSEC-2026-2680
  • PyPI/nicegui
NiceGUI: Unauthenticated log-volume denial of service in dynamic resource routes 13 Jul
  • Fix available
  • Severity - 5.3 (Medium)
PYSEC-2026-2679
  • PyPI/nicegui
NiceGUI: Local file disclosure via Docutils file insertion in ui.restructured_text() 13 Jul
  • Fix available
  • Severity - 7.5 (High)
PYSEC-2026-1703
  • PyPI/nicegui
NiceGUI has Redis connection leak via tab storage causes service degradation 07 Jul
  • Fix available
  • Severity - 5.3 (Medium)
PYSEC-2026-1702
  • PyPI/nicegui
NiceGUI apps which use `ui.sub_pages` vulnerable to zero-click XSS 07 Jul
  • Fix available
  • Severity - 7.2 (High)
PYSEC-2026-1701
  • PyPI/nicegui
NiceGUI apps are vulnerable to XSS which uses `ui.sub_pages` and render arbitrary user-provided links 07 Jul
  • Fix available
  • Severity - 6.1 (Medium)
PYSEC-2026-1698
  • PyPI/nicegui
NiceGUI is vulnerable to XSS via Unescaped URL in ui.navigate.history.push() / replace() 07 Jul
  • Fix available
  • Severity - 6.1 (Medium)
PYSEC-2026-1700
  • PyPI/nicegui
NiceGUI has a path traversal in app.add_media_files() allows arbitrary file read 07 Jul
  • Fix available
  • Severity - 7.5 (High)
PYSEC-2026-1696
  • PyPI/nicegui
NiceGUI Stored/Reflected XSS in ui.interactive_image via unsanitized SVG content 07 Jul
  • Fix available
  • Severity - 6.1 (Medium)
PYSEC-2026-1697
  • PyPI/nicegui
NiceGUI Reflected XSS in ui.add_css, ui.add_scss, and ui.add_sass via Style Injection 07 Jul
  • Fix available
  • Severity - 6.1 (Medium)
PYSEC-2026-1699
  • PyPI/nicegui
NiceGUI has a Reflected XSS 07 Jul
  • Fix available
  • Severity - 6.1 (Medium)
PYSEC-2026-1705
  • PyPI/nicegui
NiceGUI On Air authentication issue 07 Jul
  • Fix available
  • Severity - 7.5 (High)
PYSEC-2026-1704
  • PyPI/nicegui
NiceGUI allows potential access to local file system 07 Jul
  • Fix available
  • Severity - 8.2 (High)
GHSA-pq7c-x8g4-rvp6
  • PyPI/nicegui
NiceGUI: Unauthenticated log-volume denial of service in dynamic resource routes 18 May
  • Fix available
  • Severity - 5.3 (Medium)
GHSA-jfrm-rx66-g536
  • PyPI/nicegui
NiceGUI: Local file disclosure via Docutils file insertion in ui.restructured_text() 18 May
  • Fix available
  • Severity - 7.5 (High)
PYSEC-2026-2234
  • PyPI/nicegui
See record for full details 08 Apr
  • Fix available
  • Severity - 7.5 (High)
GHSA-w8wv-vfpc-hw2w
  • PyPI/nicegui
NiceGUI: Upload filename sanitization bypass via backslashes allows path traversal on Windows 08 Apr
  • Fix available
  • Severity - 5.9 (Medium)