Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-2m4f-cg75-76w2 | NiceGUI Stored/Reflected XSS in ui.interactive_image via unsanitized SVG content |
Thu, 11 Dec 2025 19:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Zauberzeug
Zauberzeug nicegui |
|
| CPEs | cpe:2.3:a:zauberzeug:nicegui:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Zauberzeug
Zauberzeug nicegui |
Tue, 09 Dec 2025 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 09 Dec 2025 10:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Nicegui
Nicegui nicegui |
|
| Vendors & Products |
Nicegui
Nicegui nicegui |
Tue, 09 Dec 2025 00:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | NiceGUI is a Python-based UI framework. Versions 3.3.1 and below are subject to a XSS vulnerability through the ui.interactive_image component of NiceGUI. The component renders SVG content using Vue's v-html directive without any sanitization. This allows attackers to inject malicious HTML or JavaScript via the SVG <foreignObject> tag whenever the image component is rendered or updated. This is particularly dangerous for dashboards or multi-user applications displaying user-generated content or annotations. This issue is fixed in version 3.4.0. | |
| Title | NiceGUI Stored/Reflected XSS in ui.interactive_image via unsanitized SVG content | |
| Weaknesses | CWE-79 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2025-12-09T16:03:45.875Z
Reserved: 2025-12-02T15:43:16.586Z
Link: CVE-2025-66470
Updated: 2025-12-09T14:17:57.442Z
Status : Analyzed
Published: 2025-12-09T01:16:54.957
Modified: 2025-12-11T18:49:47.080
Link: CVE-2025-66470
No data.
OpenCVE Enrichment
Updated: 2025-12-09T10:04:45Z
Github GHSA