Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-hxp3-63hc-5366 | NiceGUI has a path traversal in app.add_media_files() allows arbitrary file read |
Fri, 19 Dec 2025 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Zauberzeug
Zauberzeug nicegui |
|
| CPEs | cpe:2.3:a:zauberzeug:nicegui:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Zauberzeug
Zauberzeug nicegui |
Wed, 10 Dec 2025 18:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Nicegui
Nicegui nicegui |
|
| Vendors & Products |
Nicegui
Nicegui nicegui |
Wed, 10 Dec 2025 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 09 Dec 2025 21:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | NiceGUI is a Python-based UI framework. Versions 3.3.1 and below are vulnerable to directory traversal through the App.add_media_files() function, which allows a remote attacker to read arbitrary files on the server filesystem. This issue is fixed in version 3.4.0. | |
| Title | NiceGUI Path Traversal Vulnerability in app.add_media_files() Allows Arbitrary File Reading | |
| Weaknesses | CWE-22 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2025-12-10T16:50:41.291Z
Reserved: 2025-12-05T20:23:19.595Z
Link: CVE-2025-66645
Updated: 2025-12-10T16:14:23.568Z
Status : Analyzed
Published: 2025-12-09T22:16:15.930
Modified: 2025-12-19T19:00:54.200
Link: CVE-2025-66645
No data.
OpenCVE Enrichment
Updated: 2025-12-10T17:49:07Z
Github GHSA