<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-06T19:50:00.568832+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cve-2026-39844</id>
    <title>CVE-2026-39844 — NiceGUI has a Path Traversal in NiceGUI Upload Filename on Windows via Backslash Bypass of PurePosixPath Sanitization</title>
    <updated>2026-10-06T19:50:00.570597+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> zauberzeug nicegui</p>
<p>NiceGUI is a Python-based UI framework. Prior to 3.10.0, Since PurePosixPath only recognizes forward slashes (/) as path separators, an attacker can bypass this sanitization on Windows by using backslashes (\) in the upload filename. Applications that construct file paths using file.name (a pattern demonstrated in NiceGUI's bundled examples) are vulnerable to arbitrary file write on Windows. This vulnerability is fixed in 3.10.0.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/cve-2026-39844"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-w8wv-vfpc-hw2w</id>
    <title>GHSA-w8wv-vfpc-hw2w — NiceGUI: Upload filename sanitization bypass via backslashes allows path traversal on Windows</title>
    <updated>2026-10-06T19:50:00.570655+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> PyPI: nicegui</p>
<p>### Summary</p>
<p>The upload filename sanitization introduced in GHSA-9ffm-fxg3-xrhh uses `PurePosixPath(filename).name` to strip path components. Since `PurePosixPath` only recognizes forward slashes (`/`) as path separators, an attacker can bypass this sanitization on Windows by using backslashes (`\`) in the upload filename.</p>
<p>Applications that construct file paths using `file.name` (a pattern demonstrated in NiceGUI's bundled examples) are vulnerable to arbitrary file write on Windows.</p>
<p>### Details</p>
<p>The sanitization in `nicegui/elements/upload_files.py` uses:</p>
<p>```python
filename = PurePosixPath(upload.filename or '').name
```</p>
<p>`PurePosixPath` treats backslashes as literal characters, not path separators:</p>
<p>```python
&gt;&gt;&gt; PurePosixPath('..\\..\\secret\\evil.txt').name
'..\\..\\secret\\evil.txt'  # Not stripped!
```</p>
<p>When this filename is used in a path operation on Windows (e.g., `Path('uploads') / file.name`), Windows `Path` interprets backslashes as directory separators, resolving the path outside the intended directory.</p>
<p>### Impact</p>
<p>On Windows deployments of NiceGUI applications that use `file.name` in path construction:</p>
<p>- **Arbitrary file write** outside the intended upload directory
- **Potential remote code execution** through overwriting application files or placing executables in known locations
- **Data integrity loss** through overwriting existing files</p>
<p>Linux and macOS are not affected, as they treat backslashes as literal filename characters.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-w8wv-vfpc-hw2w"/>
  </entry>
</feed>
