Directory Traversal Vulnerability in NiceGUI Framework by Zauberzeug
CVE-2025-66645
7.5HIGH
What is CVE-2025-66645?
The NiceGUI framework, which is based on Python, has a vulnerability that allows attackers to exploit directory traversal through the App.add_media_files() function. This weakness lets unauthorized users read arbitrary files from the server's filesystem, potentially exposing sensitive information. The issue has been addressed in version 3.4.0, which users are encouraged to update to promptly. For more details on the vulnerability and its resolution, refer to the official advisories.
Affected Version(s)
nicegui < 3.4.0
