Junglewise Threat Intelligence

CVE-2026-45553: NiceGUI local file disclosure in ui.restructured_text

CVE-2026-45553 · Severity: high · CVSS 7.5 · Published 2026-06-02

Technologies: nicegui (PyPI). Vendors: PyPI.

Executive brief

NiceGUI is a Python framework used for building web-based user interfaces. A vulnerability in its text rendering component allows attackers to read sensitive files from the server's local storage if the application displays user-provided text. This could lead to the exposure of configuration files, API keys, database credentials, and other private data, potentially compromising the entire application environment.

Technical details

The vulnerability exists in the `ui.restructured_text()` component of NiceGUI due to an insecure configuration of the underlying Docutils library. Specifically, the `prepare_content()` function in `nicegui/elements/restructured_text.py` fails to disable file insertion and raw directives when calling `publish_parts()`. An unauthenticated remote attacker can exploit this by submitting specially crafted reStructuredText containing directives such as `include`, `csv-table` with `:file:`, or `raw` with `:file:`. If the application passes this attacker-controlled content to the renderer, the server will embed the contents of local files into the generated HTML. This issue is patched in version 3.12.0 by setting `file_insertion_enabled` and `raw_enabled` to False in the Docutils settings.

Affected products

  • zauberzeug NiceGUI <= 3.11.1

Timeline

  • 2026-05-12: patched: Version 3.12.0 released
  • 2026-05-12: advisory: GitHub Security Advisory GHSA-jfrm-rx66-g536 published
  • 2026-06-02: disclosed: NVD publication date

References

Related threats