Логотип exploitDog
bind:CVE-2025-66645
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2025-66645

Количество 2

Количество 2

nvd логотип

CVE-2025-66645

2 месяца назад

NiceGUI is a Python-based UI framework. Versions 3.3.1 and below are vulnerable to directory traversal through the App.add_media_files() function, which allows a remote attacker to read arbitrary files on the server filesystem. This issue is fixed in version 3.4.0.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-hxp3-63hc-5366

2 месяца назад

NiceGUI has a path traversal in app.add_media_files() allows arbitrary file read

CVSS3: 7.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2025-66645

NiceGUI is a Python-based UI framework. Versions 3.3.1 and below are vulnerable to directory traversal through the App.add_media_files() function, which allows a remote attacker to read arbitrary files on the server filesystem. This issue is fixed in version 3.4.0.

CVSS3: 7.5
1%
Низкий
2 месяца назад
github логотип
GHSA-hxp3-63hc-5366

NiceGUI has a path traversal in app.add_media_files() allows arbitrary file read

CVSS3: 7.5
1%
Низкий
2 месяца назад

Уязвимостей на страницу