Session Management Flaw in NiceGUI Affects Multiple Browsers
CVE-2025-21618

Currently unrated

Key Information:

Vendor

Zauberzeug

Status
Vendor
CVE Published:
6 January 2025

What is CVE-2025-21618?

NiceGUI, a user-friendly Python UI framework, has a vulnerability that allows authenticated sessions to persist across all browsers, including incognito mode, prior to version 2.9.1. This flaw raises significant security concerns, as it can lead to unauthorized access if a user's session is compromised in shared environments. The vulnerability has been addressed in the latest release, ensuring that session management works correctly across different browsing contexts.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

References

Timeline

  • Vulnerability published

.