<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Tue, 06 Oct 2026 15:05:35 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-290268</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-290268</link>
      <description>EUVD-2026-290268</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-290268</guid>
    </item>
    <item>
      <title>fkie_cve-2026-39844</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-39844</link>
      <description>&lt;p&gt;NiceGUI is a Python-based UI framework. Prior to 3.10.0, Since PurePosixPath only recognizes forward slashes (/) as path separators, an attacker can bypass this sanitization on Windows by using backslashes (\) in the upload filename. Applications that construct file paths using file.name (a pattern demonstrated in NiceGUI&amp;#39;s bundled examples) are vulnerable to arbitrary file write on Windows. This vulnerability is fixed in 3.10.0.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;NiceGUI is a Python-based UI framework. Prior to 3.10.0, Since PurePosixPath only recognizes forward slashes (/) as path separators, an attacker can bypass this sanitization on Windows by using backslashes (\) in the upload filename. Applications that construct file paths using file.name (a pattern demonstrated in NiceGUI&amp;#39;s bundled examples) are vulnerable to arbitrary file write on Windows. This vulnerability is fixed in 3.10.0.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-39844</guid>
    </item>
    <item>
      <title>GHSA-w8wv-vfpc-hw2w — NiceGUI: Upload filename sanitization bypass via backslashes allows path traversal on Windows</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-w8wv-vfpc-hw2w</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: nicegui&lt;/p&gt;
&lt;p&gt;### Summary&lt;/p&gt;
&lt;p&gt;The upload filename sanitization introduced in GHSA-9ffm-fxg3-xrhh uses `PurePosixPath(filename).name` to strip path components. Since `PurePosixPath` only recognizes forward slashes (`/`) as path separators, an attacker can bypass this sanitization on Windows by using backslashes (`\`) in the upload filename.&lt;/p&gt;
&lt;p&gt;Applications that construct file paths using `file.name` (a pattern demonstrated in NiceGUI&amp;#39;s bundled examples) are vulnerable to arbitrary file write on Windows.&lt;/p&gt;
&lt;p&gt;### Details&lt;/p&gt;
&lt;p&gt;The sanitization in `nicegui/elements/upload_files.py` uses:&lt;/p&gt;
&lt;p&gt;```python
filename = PurePosixPath(upload.filename or &amp;#39;&amp;#39;).name
```&lt;/p&gt;
&lt;p&gt;`PurePosixPath` treats backslashes as literal characters, not path separators:&lt;/p&gt;
&lt;p&gt;```python
&amp;gt;&amp;gt;&amp;gt; PurePosixPath(&amp;#39;..\\..\\secret\\evil.txt&amp;#39;).name
&amp;#39;..\\..\\secret\\evil.txt&amp;#39;  # Not stripped!
```&lt;/p&gt;
&lt;p&gt;When this filename is used in a path operation on Windows (e.g., `Path(&amp;#39;uploads&amp;#39;) / file.name`), Windows `Path` interprets backslashes as directory separators, resolving the path outside the intended directory.&lt;/p&gt;
&lt;p&gt;### Impact&lt;/p&gt;
&lt;p&gt;On Windows deployments of NiceGUI applications that use `file.name` in path construction:&lt;/p&gt;
&lt;p&gt;- **Arbitrary file write** outside the intended upload directory
- **Potential remote code execution** through overwriting application files or placing executables in known locations
- **Data integrity loss** through overwriting existing files&lt;/p&gt;
&lt;p&gt;Linux and macOS are not affected, as they treat backslashes as literal filename characters.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: nicegui&lt;/p&gt;
&lt;p&gt;### Summary&lt;/p&gt;
&lt;p&gt;The upload filename sanitization introduced in GHSA-9ffm-fxg3-xrhh uses `PurePosixPath(filename).name` to strip path components. Since `PurePosixPath` only recognizes forward slashes (`/`) as path separators, an attacker can bypass this sanitization on Windows by using backslashes (`\`) in the upload filename.&lt;/p&gt;
&lt;p&gt;Applications that construct file paths using `file.name` (a pattern demonstrated in NiceGUI&amp;#39;s bundled examples) are vulnerable to arbitrary file write on Windows.&lt;/p&gt;
&lt;p&gt;### Details&lt;/p&gt;
&lt;p&gt;The sanitization in `nicegui/elements/upload_files.py` uses:&lt;/p&gt;
&lt;p&gt;```python
filename = PurePosixPath(upload.filename or &amp;#39;&amp;#39;).name
```&lt;/p&gt;
&lt;p&gt;`PurePosixPath` treats backslashes as literal characters, not path separators:&lt;/p&gt;
&lt;p&gt;```python
&amp;gt;&amp;gt;&amp;gt; PurePosixPath(&amp;#39;..\\..\\secret\\evil.txt&amp;#39;).name
&amp;#39;..\\..\\secret\\evil.txt&amp;#39;  # Not stripped!
```&lt;/p&gt;
&lt;p&gt;When this filename is used in a path operation on Windows (e.g., `Path(&amp;#39;uploads&amp;#39;) / file.name`), Windows `Path` interprets backslashes as directory separators, resolving the path outside the intended directory.&lt;/p&gt;
&lt;p&gt;### Impact&lt;/p&gt;
&lt;p&gt;On Windows deployments of NiceGUI applications that use `file.name` in path construction:&lt;/p&gt;
&lt;p&gt;- **Arbitrary file write** outside the intended upload directory
- **Potential remote code execution** through overwriting application files or placing executables in known locations
- **Data integrity loss** through overwriting existing files&lt;/p&gt;
&lt;p&gt;Linux and macOS are not affected, as they treat backslashes as literal filename characters.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-w8wv-vfpc-hw2w</guid>
    </item>
    <item>
      <title>PYSEC-2026-2234</title>
      <link>https://cve.radiocsirt.org/vuln/pysec-2026-2234</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: nicegui&lt;/p&gt;
&lt;p&gt;NiceGUI is a Python-based UI framework. Prior to 3.10.0, Since PurePosixPath only recognizes forward slashes (/) as path separators, an attacker can bypass this sanitization on Windows by using backslashes (\) in the upload filename. Applications that construct file paths using file.name (a pattern demonstrated in NiceGUI&amp;#39;s bundled examples) are vulnerable to arbitrary file write on Windows. This vulnerability is fixed in 3.10.0.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: nicegui&lt;/p&gt;
&lt;p&gt;NiceGUI is a Python-based UI framework. Prior to 3.10.0, Since PurePosixPath only recognizes forward slashes (/) as path separators, an attacker can bypass this sanitization on Windows by using backslashes (\) in the upload filename. Applications that construct file paths using file.name (a pattern demonstrated in NiceGUI&amp;#39;s bundled examples) are vulnerable to arbitrary file write on Windows. This vulnerability is fixed in 3.10.0.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/pysec-2026-2234</guid>
    </item>
  </channel>
</rss>
