<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-06T19:18:22.407751+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cve-2025-66470</id>
    <title>CVE-2025-66470 — NiceGUI Stored/Reflected XSS in ui.interactive_image via unsanitized SVG content</title>
    <updated>2026-10-06T19:18:22.410787+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> zauberzeug nicegui</p>
<p>NiceGUI is a Python-based UI framework. Versions 3.3.1 and below are subject to a XSS vulnerability through the ui.interactive_image component of NiceGUI. The component renders SVG content using Vue's v-html directive without any sanitization. This allows attackers to inject malicious HTML or JavaScript via the SVG &lt;foreignObject&gt; tag whenever the image component is rendered or updated. This is particularly dangerous for dashboards or multi-user applications displaying user-generated content or annotations. This issue is fixed in version 3.4.0.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/cve-2025-66470"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/pysec-2026-1696</id>
    <title>PYSEC-2026-1696 — NiceGUI Stored/Reflected XSS in ui.interactive_image via unsanitized SVG content</title>
    <updated>2026-10-06T19:18:22.410849+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> PyPI: nicegui</p>
<p>### Summary
A Cross-Site Scripting (XSS) vulnerability exists in the `ui.interactive_image` component of NiceGUI (v3.3.1 and earlier). The component renders SVG content using Vue's `v-html` directive without any sanitization. This allows attackers to inject malicious HTML or JavaScript via the SVG `&lt;foreignObject&gt;` tag.</p>
<p>### Details
The vulnerability is located in `nicegui/elements/interactive_image.js`.
The component uses the following code to render content:
```javascript
&lt;g v-html="content"&gt;&lt;/g&gt;
```
Vue's v-html directive renders raw HTML strings into the DOM. If an application allows user-controlled input to be passed to the content property of an interactive image, an attacker can embed a &lt;foreignObject&gt; tag containing malicious scripts, bypassing typical image restrictions.</p>
<p>### PoC
```python
from nicegui import ui</p>
<p>@ui.page('/')
def main():
    ui.label('NiceGUI SVG XSS PoC')
    
    # Standard image loading
    img = ui.interactive_image('[https://picsum.photos/640/360](https://picsum.photos/640/360)')
    
    # Payload: Embeds raw HTML execution inside SVG
    # This executes immediately when the image component is rendered
    img.content = (
        '&lt;foreignObject&gt;'
        '&lt;body xmlns="[http://www.w3.org/1999/xhtml](http://www.w3.org/1999/xhtml)"&gt;'
        '&lt;img src=x onerror=alert("XSS-SVG")&gt;'
        '&lt;/body&gt;'
        '&lt;/foreignObject&gt;'
    )</p>
<p>ui.run()
```</p>
<p>### Impact
- Type: Reflected / Stored XSS (depending on data source)</p>
<p>- Severity: Moderate</p>
<p>- Impact:…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/pysec-2026-1696"/>
  </entry>
</feed>
