<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-06T16:22:57.834844+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cve-2025-66645</id>
    <title>CVE-2025-66645 — NiceGUI Path Traversal Vulnerability in app.add_media_files() Allows Arbitrary File Reading</title>
    <updated>2026-10-06T16:22:57.836467+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> zauberzeug nicegui</p>
<p>NiceGUI is a Python-based UI framework. Versions 3.3.1 and below are vulnerable to  directory traversal through the App.add_media_files() function, which allows a remote attacker to read arbitrary files on the server filesystem. This issue is fixed in version 3.4.0.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/cve-2025-66645"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-hxp3-63hc-5366</id>
    <title>GHSA-hxp3-63hc-5366 — NiceGUI has a path traversal in app.add_media_files() allows arbitrary file read</title>
    <updated>2026-10-06T16:22:57.836519+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> PyPI: nicegui</p>
<p>### Summary</p>
<p>A directory traversal vulnerability in NiceGUI's `App.add_media_files()` allows a remote attacker to read arbitrary files on the server filesystem.</p>
<p>### Details</p>
<p>Hello, I am Seungbin Yang, a university student studying cybersecurity. 
While reviewing the source code of the repository, I discovered a potential vulnerability and successfully verified it with a PoC.</p>
<p>The `App.add_media_files(url_path, local_directory)` method allows users to serve media files. However, the implementation lacks proper path validation.</p>
<p>```python
def add_media_files(self, url_path: str, local_directory: Union[str, Path]) -&gt; None:
    @self.get(url_path.rstrip('/') + '/{filename:path}')
    def read_item(request: Request, filename: str, nicegui_chunk_size: int = 8192) -&gt; Response:
        filepath = Path(local_directory) / filename
        if not filepath.is_file():
            raise HTTPException(status_code=404, detail='Not Found')
        return get_range_response(filepath, request, chunk_size=nicegui_chunk_size)
```
Root Cause:
1. The `{filename:path}` parameter accepts full paths, including traversal sequences like `../`.
2. The code simply joins local_directory and filename without checking if the result is still inside the local_directory.
3. There is no path sanitization or boundary check.</p>
<p>Consequence:
An attacker can use `..` to access files outside the intended directory. If the application has permission, sensitive files (e.g., /etc/hosts, source code, config files) can be…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-hxp3-63hc-5366"/>
  </entry>
</feed>
