{"schema_version":1,"title":"nicegui (PyPI) vulnerabilities","summary":"Junglewise Threat Intelligence has tracked 17 vulnerabilities in nicegui (PyPI): 0 in the last 7 days and 10 in the last 90 days, 0 of them critical and 0 exploited in the wild. The most recent, CVE-2026-21874, was published on 7 July 2026.","url":"https://junglewise.ai/threats/technologies/nicegui","json_url":"https://junglewise.ai/threats/technologies/nicegui.json","publisher":"Junglewise Threat Intelligence","license":"CC-BY-4.0","license_url":"https://creativecommons.org/licenses/by/4.0/","attribution":"Junglewise Threat Intelligence, https://junglewise.ai/threats/technologies/nicegui","sources":"NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories","kind":"technology","counts":{"high":2,"all_time":17,"critical":0,"exploited":0,"last_7_days":0,"last_30_days":0,"last_90_days":10,"last_365_days":17},"latest":[{"cve":"CVE-2026-21874","cvss":3.1,"epss":0.0056,"slug":"cve-2026-21874-nicegui-has-redis-connection-leak-via-tab-storage-causes-service","title":"PYSEC-2026-1703 - NiceGUI has Redis connection leak via tab storage causes service degradation","severity":"low","exploited":false,"published_at":"2026-07-07T16:03:17.363696+00:00","url":"https://junglewise.ai/threats/cve-2026-21874-nicegui-has-redis-connection-leak-via-tab-storage-causes-service"},{"cve":"CVE-2026-21873","cvss":3.1,"epss":0.0026,"slug":"cve-2026-21873-nicegui-apps-which-use-ui-sub-pages-vulnerable-to-zero-click-xss","title":"PYSEC-2026-1702 - NiceGUI apps which use `ui.sub_pages` vulnerable to zero-click XSS","severity":"low","exploited":false,"published_at":"2026-07-07T16:03:17.279776+00:00","url":"https://junglewise.ai/threats/cve-2026-21873-nicegui-apps-which-use-ui-sub-pages-vulnerable-to-zero-click-xss"},{"cve":"CVE-2026-21872","cvss":3.1,"epss":0.0028,"slug":"cve-2026-21872-nicegui-apps-are-vulnerable-to-xss-which-uses-ui-sub-pages-and","title":"PYSEC-2026-1701 - NiceGUI apps are vulnerable to XSS which uses `ui.sub_pages` and render arbitrary user-provided links","severity":"low","exploited":false,"published_at":"2026-07-07T16:03:17.19832+00:00","url":"https://junglewise.ai/threats/cve-2026-21872-nicegui-apps-are-vulnerable-to-xss-which-uses-ui-sub-pages-and"},{"cve":"CVE-2026-21871","cvss":3.1,"epss":0.0028,"slug":"cve-2026-21871-nicegui-is-vulnerable-to-xss-via-unescaped-url-in-ui-navigate","title":"PYSEC-2026-1698 - NiceGUI is vulnerable to XSS via Unescaped URL in ui.navigate.history.push() / replace()","severity":"low","exploited":false,"published_at":"2026-07-07T16:03:17.124842+00:00","url":"https://junglewise.ai/threats/cve-2026-21871-nicegui-is-vulnerable-to-xss-via-unescaped-url-in-ui-navigate"},{"cve":"CVE-2025-66645","cvss":3.1,"epss":0.0112,"slug":"cve-2025-66645-nicegui-has-a-path-traversal-in-app-add-media-files-allows","title":"PYSEC-2026-1700 - NiceGUI has a path traversal in app.add_media_files() allows arbitrary file read","severity":"low","exploited":false,"published_at":"2026-07-07T16:03:12.541903+00:00","url":"https://junglewise.ai/threats/cve-2025-66645-nicegui-has-a-path-traversal-in-app-add-media-files-allows"},{"cve":"CVE-2025-66470","cvss":3.1,"epss":0.0025,"slug":"cve-2025-66470-nicegui-stored-reflected-xss-in-ui-interactive-image-via","title":"PYSEC-2026-1696 - NiceGUI Stored/Reflected XSS in ui.interactive_image via unsanitized SVG content","severity":"low","exploited":false,"published_at":"2026-07-07T16:03:12.469922+00:00","url":"https://junglewise.ai/threats/cve-2025-66470-nicegui-stored-reflected-xss-in-ui-interactive-image-via"},{"cve":"CVE-2025-66469","cvss":3.1,"epss":0.0028,"slug":"cve-2025-66469-nicegui-reflected-xss-in-ui-add-css-ui-add-scss-and-ui-add-sass","title":"PYSEC-2026-1697 - NiceGUI Reflected XSS in ui.add_css, ui.add_scss, and ui.add_sass via Style Injection","severity":"low","exploited":false,"published_at":"2026-07-07T16:03:12.398225+00:00","url":"https://junglewise.ai/threats/cve-2025-66469-nicegui-reflected-xss-in-ui-add-css-ui-add-scss-and-ui-add-sass"},{"cve":"CVE-2025-53354","cvss":3.1,"epss":0.002,"slug":"cve-2025-53354-nicegui-has-a-reflected-xss","title":"PYSEC-2026-1699 - NiceGUI has a Reflected XSS","severity":"low","exploited":false,"published_at":"2026-07-07T16:03:06.332347+00:00","url":"https://junglewise.ai/threats/cve-2025-53354-nicegui-has-a-reflected-xss"},{"cve":"CVE-2025-21618","cvss":3.1,"epss":0.0038,"slug":"cve-2025-21618-nicegui-on-air-authentication-issue","title":"PYSEC-2026-1705 - NiceGUI On Air authentication issue","severity":"low","exploited":false,"published_at":"2026-07-07T14:34:48.404647+00:00","url":"https://junglewise.ai/threats/cve-2025-21618-nicegui-on-air-authentication-issue"},{"cve":"CVE-2024-32005","cvss":3.1,"epss":0.0076,"slug":"cve-2024-32005-nicegui-allows-potential-access-to-local-file-system","title":"PYSEC-2026-1704 - NiceGUI allows potential access to local file system","severity":"low","exploited":false,"published_at":"2026-07-07T11:45:38.394499+00:00","url":"https://junglewise.ai/threats/cve-2024-32005-nicegui-allows-potential-access-to-local-file-system"},{"cve":"CVE-2026-45554","cvss":5.3,"epss":0.006,"slug":"cve-2026-45554-nicegui-denial-of-service-via-log-exhaustion-in-static-asset","title":"NiceGUI denial of service via log exhaustion in static asset routes","severity":"medium","exploited":false,"published_at":"2026-06-02T16:16:41.977+00:00","url":"https://junglewise.ai/threats/cve-2026-45554-nicegui-denial-of-service-via-log-exhaustion-in-static-asset"},{"cve":"CVE-2026-45553","cvss":7.5,"epss":0.0043,"slug":"cve-2026-45553-nicegui-local-file-disclosure-in-ui-restructured-text","title":"NiceGUI local file disclosure in ui.restructured_text","severity":"high","exploited":false,"published_at":"2026-06-02T16:16:41.833+00:00","url":"https://junglewise.ai/threats/cve-2026-45553-nicegui-local-file-disclosure-in-ui-restructured-text"},{"cve":"CVE-2026-39844","cvss":5.9,"epss":0.0049,"slug":"cve-2026-39844-zauberzeug-nicegui-path-traversal-in-file-upload-on-windows","title":"Zauberzeug NiceGUI path traversal in file upload on Windows","severity":"medium","exploited":false,"published_at":"2026-04-08T21:16:59.883+00:00","url":"https://junglewise.ai/threats/cve-2026-39844-zauberzeug-nicegui-path-traversal-in-file-upload-on-windows"},{"cve":"CVE-2026-33332","cvss":3.1,"epss":0.0069,"slug":"cve-2026-33332-nicegui-s-unvalidated-chunk-size-parameter-in-media-routes-can","title":"PYSEC-2026-2233 - NiceGUI is a Python-based UI framework. Prior to version 3.9.0, NiceGUI's app.add_media_file() and app.add_media_files() media routes accept","severity":"low","exploited":false,"published_at":"2026-03-24T20:16:28.743+00:00","url":"https://junglewise.ai/threats/cve-2026-33332-nicegui-s-unvalidated-chunk-size-parameter-in-media-routes-can"},{"cve":"CVE-2026-27156","cvss":3.1,"epss":0.0027,"slug":"cve-2026-27156-nicegui-vulnerable-to-xss-via-code-injection-during-client-side","title":"PYSEC-2026-2232 - NiceGUI is a Python-based UI framework. Prior to version 3.8.0, several NiceGUI APIs that execute methods on client-side elements (`Element.","severity":"low","exploited":false,"published_at":"2026-02-24T18:29:33.49+00:00","url":"https://junglewise.ai/threats/cve-2026-27156-nicegui-vulnerable-to-xss-via-code-injection-during-client-side"},{"cve":"CVE-2026-25516","cvss":3.1,"epss":0.0029,"slug":"cve-2026-25516-nicegui-s-xss-vulnerability-in-ui-markdown-allows-arbitrary","title":"PYSEC-2026-2231 - NiceGUI is a Python-based UI framework. The ui.markdown() component uses the markdown2 library to convert markdown content to HTML, which is","severity":"low","exploited":false,"published_at":"2026-02-06T22:16:11.3+00:00","url":"https://junglewise.ai/threats/cve-2026-25516-nicegui-s-xss-vulnerability-in-ui-markdown-allows-arbitrary"},{"cve":"CVE-2026-25732","cvss":7.5,"epss":0.03,"slug":"cve-2026-25732-nicegui-path-traversal-in-fileupload-save","title":"NiceGUI path traversal in FileUpload.save","severity":"high","exploited":false,"published_at":"2026-02-05T21:08:53+00:00","url":"https://junglewise.ai/threats/cve-2026-25732-nicegui-path-traversal-in-fileupload-save"}],"weekly":[{"week":"2026-06-29","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-06","critical":0,"exploited":0,"vulnerabilities":10},{"week":"2026-07-13","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-20","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-27","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-03","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-10","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-17","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-24","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-31","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-07","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-14","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-21","critical":0,"exploited":0,"vulnerabilities":0}],"related":[{"name":"open-webui (PyPI)","slug":"open-webui","vulnerabilities":156,"url":"https://junglewise.ai/threats/technologies/open-webui"},{"name":"nltk (PyPI)","slug":"nltk","vulnerabilities":74,"url":"https://junglewise.ai/threats/technologies/nltk"},{"name":"picklescan (PyPI)","slug":"picklescan","vulnerabilities":74,"url":"https://junglewise.ai/threats/technologies/picklescan"},{"name":"openbabel (PyPI)","slug":"openbabel","vulnerabilities":48,"url":"https://junglewise.ai/threats/technologies/openbabel"},{"name":"apache-superset (PyPI)","slug":"apache-superset","vulnerabilities":44,"url":"https://junglewise.ai/threats/technologies/apache-superset"},{"name":"apache-airflow (PyPI)","slug":"apache-airflow","vulnerabilities":40,"url":"https://junglewise.ai/threats/technologies/apache-airflow"},{"name":"tensorflow-gpu (PyPI)","slug":"tensorflow-gpu","vulnerabilities":37,"url":"https://junglewise.ai/threats/technologies/tensorflow-gpu"},{"name":"tensorflow-cpu (PyPI)","slug":"tensorflow-cpu","vulnerabilities":34,"url":"https://junglewise.ai/threats/technologies/tensorflow-cpu"},{"name":"weblate (PyPI)","slug":"weblate","vulnerabilities":33,"url":"https://junglewise.ai/threats/technologies/weblate"},{"name":"mcp-atlassian (PyPI)","slug":"mcp-atlassian","vulnerabilities":30,"url":"https://junglewise.ai/threats/technologies/mcp-atlassian"},{"name":"crawl4ai (PyPI)","slug":"crawl4ai","vulnerabilities":28,"url":"https://junglewise.ai/threats/technologies/crawl4ai"},{"name":"moin (PyPI)","slug":"moin","vulnerabilities":28,"url":"https://junglewise.ai/threats/technologies/moin"}],"technology":{"hub":true,"name":"nicegui (PyPI)","slug":"nicegui","vendor":{"name":"PyPI","slug":"pypi","url":"https://junglewise.ai/threats/vendors/pypi"},"aliases":[],"homepage":"https://nicegui.io/","repo_url":"https://github.com/zauberzeug/nicegui","description":"NiceGUI is a Python-based framework for creating web-based user interfaces.","url":"https://junglewise.ai/threats/technologies/nicegui"},"most_severe":[{"cve":"CVE-2026-25732","cvss":7.5,"epss":0.03,"slug":"cve-2026-25732-nicegui-path-traversal-in-fileupload-save","title":"NiceGUI path traversal in FileUpload.save","severity":"high","exploited":false,"published_at":"2026-02-05T21:08:53+00:00","url":"https://junglewise.ai/threats/cve-2026-25732-nicegui-path-traversal-in-fileupload-save"},{"cve":"CVE-2026-45553","cvss":7.5,"epss":0.0043,"slug":"cve-2026-45553-nicegui-local-file-disclosure-in-ui-restructured-text","title":"NiceGUI local file disclosure in ui.restructured_text","severity":"high","exploited":false,"published_at":"2026-06-02T16:16:41.833+00:00","url":"https://junglewise.ai/threats/cve-2026-45553-nicegui-local-file-disclosure-in-ui-restructured-text"},{"cve":"CVE-2026-39844","cvss":5.9,"epss":0.0049,"slug":"cve-2026-39844-zauberzeug-nicegui-path-traversal-in-file-upload-on-windows","title":"Zauberzeug NiceGUI path traversal in file upload on Windows","severity":"medium","exploited":false,"published_at":"2026-04-08T21:16:59.883+00:00","url":"https://junglewise.ai/threats/cve-2026-39844-zauberzeug-nicegui-path-traversal-in-file-upload-on-windows"},{"cve":"CVE-2026-45554","cvss":5.3,"epss":0.006,"slug":"cve-2026-45554-nicegui-denial-of-service-via-log-exhaustion-in-static-asset","title":"NiceGUI denial of service via log exhaustion in static asset routes","severity":"medium","exploited":false,"published_at":"2026-06-02T16:16:41.977+00:00","url":"https://junglewise.ai/threats/cve-2026-45554-nicegui-denial-of-service-via-log-exhaustion-in-static-asset"},{"cve":"CVE-2025-66645","cvss":3.1,"epss":0.0112,"slug":"cve-2025-66645-nicegui-has-a-path-traversal-in-app-add-media-files-allows","title":"PYSEC-2026-1700 - NiceGUI has a path traversal in app.add_media_files() allows arbitrary file read","severity":"low","exploited":false,"published_at":"2026-07-07T16:03:12.541903+00:00","url":"https://junglewise.ai/threats/cve-2025-66645-nicegui-has-a-path-traversal-in-app-add-media-files-allows"},{"cve":"CVE-2024-32005","cvss":3.1,"epss":0.0076,"slug":"cve-2024-32005-nicegui-allows-potential-access-to-local-file-system","title":"PYSEC-2026-1704 - NiceGUI allows potential access to local file system","severity":"low","exploited":false,"published_at":"2026-07-07T11:45:38.394499+00:00","url":"https://junglewise.ai/threats/cve-2024-32005-nicegui-allows-potential-access-to-local-file-system"},{"cve":"CVE-2026-33332","cvss":3.1,"epss":0.0069,"slug":"cve-2026-33332-nicegui-s-unvalidated-chunk-size-parameter-in-media-routes-can","title":"PYSEC-2026-2233 - NiceGUI is a Python-based UI framework. Prior to version 3.9.0, NiceGUI's app.add_media_file() and app.add_media_files() media routes accept","severity":"low","exploited":false,"published_at":"2026-03-24T20:16:28.743+00:00","url":"https://junglewise.ai/threats/cve-2026-33332-nicegui-s-unvalidated-chunk-size-parameter-in-media-routes-can"},{"cve":"CVE-2026-21874","cvss":3.1,"epss":0.0056,"slug":"cve-2026-21874-nicegui-has-redis-connection-leak-via-tab-storage-causes-service","title":"PYSEC-2026-1703 - NiceGUI has Redis connection leak via tab storage causes service degradation","severity":"low","exploited":false,"published_at":"2026-07-07T16:03:17.363696+00:00","url":"https://junglewise.ai/threats/cve-2026-21874-nicegui-has-redis-connection-leak-via-tab-storage-causes-service"},{"cve":"CVE-2025-21618","cvss":3.1,"epss":0.0038,"slug":"cve-2025-21618-nicegui-on-air-authentication-issue","title":"PYSEC-2026-1705 - NiceGUI On Air authentication issue","severity":"low","exploited":false,"published_at":"2026-07-07T14:34:48.404647+00:00","url":"https://junglewise.ai/threats/cve-2025-21618-nicegui-on-air-authentication-issue"},{"cve":"CVE-2026-25516","cvss":3.1,"epss":0.0029,"slug":"cve-2026-25516-nicegui-s-xss-vulnerability-in-ui-markdown-allows-arbitrary","title":"PYSEC-2026-2231 - NiceGUI is a Python-based UI framework. The ui.markdown() component uses the markdown2 library to convert markdown content to HTML, which is","severity":"low","exploited":false,"published_at":"2026-02-06T22:16:11.3+00:00","url":"https://junglewise.ai/threats/cve-2026-25516-nicegui-s-xss-vulnerability-in-ui-markdown-allows-arbitrary"}],"generated_at":"2026-09-26T13:07:00.120236+00:00"}