<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Tue, 06 Oct 2026 17:14:00 +0000</lastBuildDate>
    <item>
      <title>CVE-2026-25732 — NiceGUI's Path Traversal via Unsanitized FileUpload.name Enables Arbitrary File Write</title>
      <link>https://cve.radiocsirt.org/vuln/cve-2026-25732</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; zauberzeug nicegui&lt;/p&gt;
&lt;p&gt;NiceGUI is a Python-based UI framework. Prior to 3.7.0, NiceGUI&amp;#39;s FileUpload.name property exposes client-supplied filename metadata without sanitization, enabling path traversal when developers use the pattern UPLOAD_DIR / file.name. Malicious filenames containing ../ sequences allow attackers to write files outside intended directories, with potential for remote code execution through application file overwrites in vulnerable deployment patterns. This design creates a prevalent security footgun affecting applications following common community patterns. Note: Exploitation requires application code incorporating file.name into filesystem paths without sanitization. Applications using fixed paths, generated filenames, or explicit sanitization are not affected. This vulnerability is fixed in 3.7.0.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; zauberzeug nicegui&lt;/p&gt;
&lt;p&gt;NiceGUI is a Python-based UI framework. Prior to 3.7.0, NiceGUI&amp;#39;s FileUpload.name property exposes client-supplied filename metadata without sanitization, enabling path traversal when developers use the pattern UPLOAD_DIR / file.name. Malicious filenames containing ../ sequences allow attackers to write files outside intended directories, with potential for remote code execution through application file overwrites in vulnerable deployment patterns. This design creates a prevalent security footgun affecting applications following common community patterns. Note: Exploitation requires application code incorporating file.name into filesystem paths without sanitization. Applications using fixed paths, generated filenames, or explicit sanitization are not affected. This vulnerability is fixed in 3.7.0.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cve-2026-25732</guid>
    </item>
    <item>
      <title>GHSA-9ffm-fxg3-xrhh — NiceGUI's Path Traversal via Unsanitized FileUpload.name Enables Arbitrary File Write</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-9ffm-fxg3-xrhh</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: nicegui&lt;/p&gt;
&lt;p&gt;### Summary
NiceGUI&amp;#39;s `FileUpload.name` property exposes client-supplied filename metadata without sanitization, enabling path traversal when developers use the pattern `UPLOAD_DIR / file.name`. Malicious filenames containing `../` sequences allow attackers to write files outside intended directories, with potential for remote code execution through application file overwrites in vulnerable deployment patterns. This design creates a prevalent security footgun affecting applications following common community patterns.&lt;/p&gt;
&lt;p&gt;**Note**: Exploitation requires application code incorporating `file.name` into filesystem paths without sanitization. Applications using fixed paths, generated filenames, or explicit sanitization are not affected.&lt;/p&gt;
&lt;p&gt;### Details
**Vulnerable Component**: `nicegui/elements/upload_files.py` ([upload_files.py#L79-L82](https://github.com/zauberzeug/nicegui/blob/main/nicegui/elements/upload_files.py#L79-L82) and [upload_files.py#L110-L115](https://github.com/zauberzeug/nicegui/blob/main/nicegui/elements/upload_files.py#L110-L115))&lt;/p&gt;
&lt;p&gt;**Affected Methods**: `SmallFileUpload.save()`and `LargeFileUpload.save()`&lt;/p&gt;
&lt;p&gt;```py
async def save(self, path: str | Path) -&amp;gt; None:
    target = Path(path)
    target.parent.mkdir(parents=True, exist_ok=True)
    await run.io_bound(target.write_bytes, self._data)
```&lt;/p&gt;
&lt;p&gt;**Root Cause**: The `save()` method performs no validation on the provided path parameter. It accepts:
- Relative paths with `../` sequences
- Absolute paths
- Any file system…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: nicegui&lt;/p&gt;
&lt;p&gt;### Summary
NiceGUI&amp;#39;s `FileUpload.name` property exposes client-supplied filename metadata without sanitization, enabling path traversal when developers use the pattern `UPLOAD_DIR / file.name`. Malicious filenames containing `../` sequences allow attackers to write files outside intended directories, with potential for remote code execution through application file overwrites in vulnerable deployment patterns. This design creates a prevalent security footgun affecting applications following common community patterns.&lt;/p&gt;
&lt;p&gt;**Note**: Exploitation requires application code incorporating `file.name` into filesystem paths without sanitization. Applications using fixed paths, generated filenames, or explicit sanitization are not affected.&lt;/p&gt;
&lt;p&gt;### Details
**Vulnerable Component**: `nicegui/elements/upload_files.py` ([upload_files.py#L79-L82](https://github.com/zauberzeug/nicegui/blob/main/nicegui/elements/upload_files.py#L79-L82) and [upload_files.py#L110-L115](https://github.com/zauberzeug/nicegui/blob/main/nicegui/elements/upload_files.py#L110-L115))&lt;/p&gt;
&lt;p&gt;**Affected Methods**: `SmallFileUpload.save()`and `LargeFileUpload.save()`&lt;/p&gt;
&lt;p&gt;```py
async def save(self, path: str | Path) -&amp;gt; None:
    target = Path(path)
    target.parent.mkdir(parents=True, exist_ok=True)
    await run.io_bound(target.write_bytes, self._data)
```&lt;/p&gt;
&lt;p&gt;**Root Cause**: The `save()` method performs no validation on the provided path parameter. It accepts:
- Relative paths with `../` sequences
- Absolute paths
- Any file system…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-9ffm-fxg3-xrhh</guid>
    </item>
  </channel>
</rss>
