<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Tue, 06 Oct 2026 21:55:51 +0000</lastBuildDate>
    <item>
      <title>CVE-2026-25516 — NiceGUI's XSS vulnerability in ui.markdown() allows arbitrary JavaScript execution through unsanitized HTML content</title>
      <link>https://cve.radiocsirt.org/vuln/cve-2026-25516</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; zauberzeug nicegui&lt;/p&gt;
&lt;p&gt;NiceGUI is a Python-based UI framework. The ui.markdown() component uses the markdown2 library to convert markdown content to HTML, which is then rendered via innerHTML. By default, markdown2 allows raw HTML to pass through unchanged. This means that if an application renders user-controlled content through ui.markdown(), an attacker can inject malicious HTML containing JavaScript event handlers. Unlike other NiceGUI components that render HTML (ui.html(), ui.chat_message(), ui.interactive_image()), the ui.markdown() component does not provide or require a sanitize parameter, leaving applications vulnerable to XSS attacks. This vulnerability is fixed in 3.7.0.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; zauberzeug nicegui&lt;/p&gt;
&lt;p&gt;NiceGUI is a Python-based UI framework. The ui.markdown() component uses the markdown2 library to convert markdown content to HTML, which is then rendered via innerHTML. By default, markdown2 allows raw HTML to pass through unchanged. This means that if an application renders user-controlled content through ui.markdown(), an attacker can inject malicious HTML containing JavaScript event handlers. Unlike other NiceGUI components that render HTML (ui.html(), ui.chat_message(), ui.interactive_image()), the ui.markdown() component does not provide or require a sanitize parameter, leaving applications vulnerable to XSS attacks. This vulnerability is fixed in 3.7.0.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cve-2026-25516</guid>
    </item>
    <item>
      <title>GHSA-v82v-c5x8-w282 — NiceGUI's XSS vulnerability in ui.markdown() allows arbitrary JavaScript execution through unsanitized HTML content</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-v82v-c5x8-w282</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: nicegui&lt;/p&gt;
&lt;p&gt;## Description&lt;/p&gt;
&lt;p&gt;The `ui.markdown()` component uses the `markdown2` library to convert markdown content to HTML, which is then rendered via `innerHTML`. By default, `markdown2` allows raw HTML to pass through unchanged. This means that if an application renders user-controlled content through `ui.markdown()`, an attacker can inject malicious HTML containing JavaScript event handlers.&lt;/p&gt;
&lt;p&gt;Unlike other NiceGUI components that render HTML (`ui.html()`, `ui.chat_message()`, `ui.interactive_image()`), the `ui.markdown()` component does not provide or require a `sanitize` parameter, leaving applications vulnerable to XSS attacks.&lt;/p&gt;
&lt;p&gt;## Proof of Concept&lt;/p&gt;
&lt;p&gt;```python
from nicegui import ui&lt;/p&gt;
&lt;p&gt;# User-controlled input containing malicious payload
user_input = &amp;#39;Hello! &amp;lt;img src=x onerror=&amp;#34;alert(\&amp;#39;XSS\&amp;#39;)&amp;#34;&amp;gt;&amp;#39;&lt;/p&gt;
&lt;p&gt;ui.markdown(user_input)  # XSS executes when page loads&lt;/p&gt;
&lt;p&gt;ui.run()
```&lt;/p&gt;
&lt;p&gt;When this page loads, the JavaScript in the `onerror` handler executes, potentially allowing an attacker to:
- Steal session cookies or authentication tokens
- Perform actions on behalf of the user
- Redirect users to malicious sites
- Modify page content&lt;/p&gt;
&lt;p&gt;## Impact&lt;/p&gt;
&lt;p&gt;Applications that render user-provided content through `ui.markdown()` are vulnerable to stored or reflected XSS attacks. This is particularly concerning for:
- Chat applications displaying user messages
- CMS or documentation systems with user-editable content
- Any application that displays markdown from untrusted sources&lt;/p&gt;
&lt;p&gt;## Remediation&lt;/p&gt;
&lt;p&gt;A release has been p…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: nicegui&lt;/p&gt;
&lt;p&gt;## Description&lt;/p&gt;
&lt;p&gt;The `ui.markdown()` component uses the `markdown2` library to convert markdown content to HTML, which is then rendered via `innerHTML`. By default, `markdown2` allows raw HTML to pass through unchanged. This means that if an application renders user-controlled content through `ui.markdown()`, an attacker can inject malicious HTML containing JavaScript event handlers.&lt;/p&gt;
&lt;p&gt;Unlike other NiceGUI components that render HTML (`ui.html()`, `ui.chat_message()`, `ui.interactive_image()`), the `ui.markdown()` component does not provide or require a `sanitize` parameter, leaving applications vulnerable to XSS attacks.&lt;/p&gt;
&lt;p&gt;## Proof of Concept&lt;/p&gt;
&lt;p&gt;```python
from nicegui import ui&lt;/p&gt;
&lt;p&gt;# User-controlled input containing malicious payload
user_input = &amp;#39;Hello! &amp;lt;img src=x onerror=&amp;#34;alert(\&amp;#39;XSS\&amp;#39;)&amp;#34;&amp;gt;&amp;#39;&lt;/p&gt;
&lt;p&gt;ui.markdown(user_input)  # XSS executes when page loads&lt;/p&gt;
&lt;p&gt;ui.run()
```&lt;/p&gt;
&lt;p&gt;When this page loads, the JavaScript in the `onerror` handler executes, potentially allowing an attacker to:
- Steal session cookies or authentication tokens
- Perform actions on behalf of the user
- Redirect users to malicious sites
- Modify page content&lt;/p&gt;
&lt;p&gt;## Impact&lt;/p&gt;
&lt;p&gt;Applications that render user-provided content through `ui.markdown()` are vulnerable to stored or reflected XSS attacks. This is particularly concerning for:
- Chat applications displaying user messages
- CMS or documentation systems with user-editable content
- Any application that displays markdown from untrusted sources&lt;/p&gt;
&lt;p&gt;## Remediation&lt;/p&gt;
&lt;p&gt;A release has been p…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-v82v-c5x8-w282</guid>
    </item>
  </channel>
</rss>
