Technology · PyPI
nicegui (PyPI) vulnerabilities
Updated . Rebuilt every hour.
Junglewise Threat Intelligence has tracked 17 vulnerabilities in nicegui (PyPI): 0 in the last 7 days and 10 in the last 90 days, 0 of them critical and 0 exploited in the wild. The most recent, CVE-2026-21874, was published on 7 July 2026.
- Last 7 days
- 0
- Last 90 days
- 10
- Critical, all time
- 0
- Exploited in the wild
- 0
About nicegui (PyPI)
NiceGUI is a Python-based framework for creating web-based user interfaces.
Latest nicegui (PyPI) vulnerabilities
- CVE-2026-21874: PYSEC-2026-1703 - NiceGUI has Redis connection leak via tab storage causes service degradationlowCVSS 3.1EPSS 0.6%
- CVE-2026-21873: PYSEC-2026-1702 - NiceGUI apps which use `ui.sub_pages` vulnerable to zero-click XSSlowCVSS 3.1EPSS 0.3%
- CVE-2026-21872: PYSEC-2026-1701 - NiceGUI apps are vulnerable to XSS which uses `ui.sub_pages` and render arbitrary user-provided linkslowCVSS 3.1EPSS 0.3%
- CVE-2026-21871: PYSEC-2026-1698 - NiceGUI is vulnerable to XSS via Unescaped URL in ui.navigate.history.push() / replace()lowCVSS 3.1EPSS 0.3%
- CVE-2025-66645: PYSEC-2026-1700 - NiceGUI has a path traversal in app.add_media_files() allows arbitrary file readlowCVSS 3.1EPSS 1.1%
- CVE-2025-66470: PYSEC-2026-1696 - NiceGUI Stored/Reflected XSS in ui.interactive_image via unsanitized SVG contentlowCVSS 3.1EPSS 0.3%
- CVE-2025-66469: PYSEC-2026-1697 - NiceGUI Reflected XSS in ui.add_css, ui.add_scss, and ui.add_sass via Style InjectionlowCVSS 3.1EPSS 0.3%
- CVE-2025-53354: PYSEC-2026-1699 - NiceGUI has a Reflected XSSlowCVSS 3.1EPSS 0.2%
- CVE-2025-21618: PYSEC-2026-1705 - NiceGUI On Air authentication issuelowCVSS 3.1EPSS 0.4%
- CVE-2024-32005: PYSEC-2026-1704 - NiceGUI allows potential access to local file systemlowCVSS 3.1EPSS 0.8%
- CVE-2026-45554: NiceGUI denial of service via log exhaustion in static asset routesmediumCVSS 5.3EPSS 0.6%
- CVE-2026-45553: NiceGUI local file disclosure in ui.restructured_texthighCVSS 7.5EPSS 0.4%
- CVE-2026-39844: Zauberzeug NiceGUI path traversal in file upload on WindowsmediumCVSS 5.9EPSS 0.5%
- CVE-2026-33332: PYSEC-2026-2233 - NiceGUI is a Python-based UI framework. Prior to version 3.9.0, NiceGUI's app.add_media_file() and…lowCVSS 3.1EPSS 0.7%
- CVE-2026-27156: PYSEC-2026-2232 - NiceGUI is a Python-based UI framework. Prior to version 3.8.0, several NiceGUI APIs that execute…lowCVSS 3.1EPSS 0.3%
- CVE-2026-25516: PYSEC-2026-2231 - NiceGUI is a Python-based UI framework. The ui.markdown() component uses the markdown2 library to…lowCVSS 3.1EPSS 0.3%
- CVE-2026-25732: NiceGUI path traversal in FileUpload.savehighCVSS 7.5EPSS 3.0%
Most severe nicegui (PyPI) vulnerabilities
Exploited in the wild first, then by severity and CVSS score.
- CVE-2026-25732: NiceGUI path traversal in FileUpload.savehighCVSS 7.5EPSS 3.0%
- CVE-2026-45553: NiceGUI local file disclosure in ui.restructured_texthighCVSS 7.5EPSS 0.4%
- CVE-2026-39844: Zauberzeug NiceGUI path traversal in file upload on WindowsmediumCVSS 5.9EPSS 0.5%
- CVE-2026-45554: NiceGUI denial of service via log exhaustion in static asset routesmediumCVSS 5.3EPSS 0.6%
- CVE-2025-66645: PYSEC-2026-1700 - NiceGUI has a path traversal in app.add_media_files() allows arbitrary file readlowCVSS 3.1EPSS 1.1%
- CVE-2024-32005: PYSEC-2026-1704 - NiceGUI allows potential access to local file systemlowCVSS 3.1EPSS 0.8%
- CVE-2026-33332: PYSEC-2026-2233 - NiceGUI is a Python-based UI framework. Prior to version 3.9.0, NiceGUI's app.add_media_file() and…lowCVSS 3.1EPSS 0.7%
- CVE-2026-21874: PYSEC-2026-1703 - NiceGUI has Redis connection leak via tab storage causes service degradationlowCVSS 3.1EPSS 0.6%
- CVE-2025-21618: PYSEC-2026-1705 - NiceGUI On Air authentication issuelowCVSS 3.1EPSS 0.4%
- CVE-2026-25516: PYSEC-2026-2231 - NiceGUI is a Python-based UI framework. The ui.markdown() component uses the markdown2 library to…lowCVSS 3.1EPSS 0.3%
Vulnerabilities per week
The last 13 weeks, by the week each vulnerability was published.
| Week of | Bar | Vulns | Critical |
|---|---|---|---|
| 29 Jun 2026 | 0 | 0 | |
| 6 Jul 2026 | 10 | 0 | |
| 13 Jul 2026 | 0 | 0 | |
| 20 Jul 2026 | 0 | 0 | |
| 27 Jul 2026 | 0 | 0 | |
| 3 Aug 2026 | 0 | 0 | |
| 10 Aug 2026 | 0 | 0 | |
| 17 Aug 2026 | 0 | 0 | |
| 24 Aug 2026 | 0 | 0 | |
| 31 Aug 2026 | 0 | 0 | |
| 7 Sep 2026 | 0 | 0 | |
| 14 Sep 2026 | 0 | 0 | |
| 21 Sep 2026 | 0 | 0 |
How this is built
Junglewise Threat Intelligence collects vulnerabilities from NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories, and matches each one to the technologies and vendors it affects. Dates are the date a vulnerability was published, in UTC.
The pages are rebuilt from the database every hour. Frozen weekly and monthly reports never change once published, so they can be cited.
Use this data
The same data is at https://junglewise.ai/threats/technologies/nicegui.json, for scripts and language models. It is free to reuse under CC BY 4.0 with a link back to this page.
Cite as: Junglewise Threat Intelligence, "nicegui (PyPI) vulnerabilities", https://junglewise.ai/threats/technologies/nicegui, 26 September 2026.