<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Tue, 06 Oct 2026 19:34:48 +0000</lastBuildDate>
    <item>
      <title>CVE-2025-66645 — NiceGUI Path Traversal Vulnerability in app.add_media_files() Allows Arbitrary File Reading</title>
      <link>https://cve.radiocsirt.org/vuln/cve-2025-66645</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; zauberzeug nicegui&lt;/p&gt;
&lt;p&gt;NiceGUI is a Python-based UI framework. Versions 3.3.1 and below are vulnerable to  directory traversal through the App.add_media_files() function, which allows a remote attacker to read arbitrary files on the server filesystem. This issue is fixed in version 3.4.0.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; zauberzeug nicegui&lt;/p&gt;
&lt;p&gt;NiceGUI is a Python-based UI framework. Versions 3.3.1 and below are vulnerable to  directory traversal through the App.add_media_files() function, which allows a remote attacker to read arbitrary files on the server filesystem. This issue is fixed in version 3.4.0.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cve-2025-66645</guid>
    </item>
    <item>
      <title>PYSEC-2026-1700 — NiceGUI has a path traversal in app.add_media_files() allows arbitrary file read</title>
      <link>https://cve.radiocsirt.org/vuln/pysec-2026-1700</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: nicegui&lt;/p&gt;
&lt;p&gt;### Summary&lt;/p&gt;
&lt;p&gt;A directory traversal vulnerability in NiceGUI&amp;#39;s `App.add_media_files()` allows a remote attacker to read arbitrary files on the server filesystem.&lt;/p&gt;
&lt;p&gt;### Details&lt;/p&gt;
&lt;p&gt;Hello, I am Seungbin Yang, a university student studying cybersecurity. 
While reviewing the source code of the repository, I discovered a potential vulnerability and successfully verified it with a PoC.&lt;/p&gt;
&lt;p&gt;The `App.add_media_files(url_path, local_directory)` method allows users to serve media files. However, the implementation lacks proper path validation.&lt;/p&gt;
&lt;p&gt;```python
def add_media_files(self, url_path: str, local_directory: Union[str, Path]) -&amp;gt; None:
    @self.get(url_path.rstrip(&amp;#39;/&amp;#39;) + &amp;#39;/{filename:path}&amp;#39;)
    def read_item(request: Request, filename: str, nicegui_chunk_size: int = 8192) -&amp;gt; Response:
        filepath = Path(local_directory) / filename
        if not filepath.is_file():
            raise HTTPException(status_code=404, detail=&amp;#39;Not Found&amp;#39;)
        return get_range_response(filepath, request, chunk_size=nicegui_chunk_size)
```
Root Cause:
1. The `{filename:path}` parameter accepts full paths, including traversal sequences like `../`.
2. The code simply joins local_directory and filename without checking if the result is still inside the local_directory.
3. There is no path sanitization or boundary check.&lt;/p&gt;
&lt;p&gt;Consequence:
An attacker can use `..` to access files outside the intended directory. If the application has permission, sensitive files (e.g., /etc/hosts, source code, config files) can be…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: nicegui&lt;/p&gt;
&lt;p&gt;### Summary&lt;/p&gt;
&lt;p&gt;A directory traversal vulnerability in NiceGUI&amp;#39;s `App.add_media_files()` allows a remote attacker to read arbitrary files on the server filesystem.&lt;/p&gt;
&lt;p&gt;### Details&lt;/p&gt;
&lt;p&gt;Hello, I am Seungbin Yang, a university student studying cybersecurity. 
While reviewing the source code of the repository, I discovered a potential vulnerability and successfully verified it with a PoC.&lt;/p&gt;
&lt;p&gt;The `App.add_media_files(url_path, local_directory)` method allows users to serve media files. However, the implementation lacks proper path validation.&lt;/p&gt;
&lt;p&gt;```python
def add_media_files(self, url_path: str, local_directory: Union[str, Path]) -&amp;gt; None:
    @self.get(url_path.rstrip(&amp;#39;/&amp;#39;) + &amp;#39;/{filename:path}&amp;#39;)
    def read_item(request: Request, filename: str, nicegui_chunk_size: int = 8192) -&amp;gt; Response:
        filepath = Path(local_directory) / filename
        if not filepath.is_file():
            raise HTTPException(status_code=404, detail=&amp;#39;Not Found&amp;#39;)
        return get_range_response(filepath, request, chunk_size=nicegui_chunk_size)
```
Root Cause:
1. The `{filename:path}` parameter accepts full paths, including traversal sequences like `../`.
2. The code simply joins local_directory and filename without checking if the result is still inside the local_directory.
3. There is no path sanitization or boundary check.&lt;/p&gt;
&lt;p&gt;Consequence:
An attacker can use `..` to access files outside the intended directory. If the application has permission, sensitive files (e.g., /etc/hosts, source code, config files) can be…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/pysec-2026-1700</guid>
    </item>
  </channel>
</rss>
