{"data":{"ecosystem":"pypi","name":"nicegui","url":"https://aisecwatch.com/packages/pypi/nicegui","latestVersion":"3.18.0","firstReleaseAt":"2021-05-14T05:54:20.225Z","repository":"https://github.com/zauberzeug/nicegui","llm":{"exposure":"none","depth":null,"integratedAt":null,"integratedVersion":null,"sdks":[],"path":[]},"authority":{"profile":["filesystem","http"],"fromDependencies":["pypi:aiofiles","pypi:aiohttp","pypi:httpx"]},"dependencies":[{"ecosystem":"pypi","name":"aiofiles","versionSpec":">=23.1.0","scope":"runtime"},{"ecosystem":"pypi","name":"aiohttp","versionSpec":">=3.14.3","scope":"runtime"},{"ecosystem":"pypi","name":"altair","versionSpec":">=6.0.0","scope":"extra:altair"},{"ecosystem":"pypi","name":"anyio","versionSpec":">=4.14.2","scope":"runtime"},{"ecosystem":"pypi","name":"anywidget","versionSpec":">=0.9.21","scope":"extra:anywidget"},{"ecosystem":"pypi","name":"certifi","versionSpec":">=2024.7.4","scope":"runtime"},{"ecosystem":"pypi","name":"docutils","versionSpec":">=0.19.0","scope":"runtime"},{"ecosystem":"pypi","name":"fastapi","versionSpec":"!=0.123.5,>=0.109.1","scope":"runtime"},{"ecosystem":"pypi","name":"fonttools","versionSpec":">=4.60.2","scope":"extra:matplotlib"},{"ecosystem":"pypi","name":"h11","versionSpec":">=0.16.0","scope":"runtime"},{"ecosystem":"pypi","name":"httpx","versionSpec":">=0.24.0","scope":"runtime"},{"ecosystem":"pypi","name":"idna","versionSpec":">=3.15","scope":"runtime"},{"ecosystem":"pypi","name":"ifaddr","versionSpec":">=0.2.0","scope":"runtime"},{"ecosystem":"pypi","name":"itsdangerous","versionSpec":"<3,>=2.1.2","scope":"runtime"},{"ecosystem":"pypi","name":"jinja2","versionSpec":"<4,>=3.1.6","scope":"runtime"},{"ecosystem":"pypi","name":"markdown2","versionSpec":"!=2.4.11,>=2.4.7","scope":"runtime"},{"ecosystem":"pypi","name":"matplotlib","versionSpec":"<4,>=3.5.0","scope":"extra:matplotlib"},{"ecosystem":"pypi","name":"multidict","versionSpec":">=6.9.1","scope":"runtime"},{"ecosystem":"pypi","name":"nicegui-highcharts","versionSpec":"<4,>=3.5.0","scope":"extra:highcharts"},{"ecosystem":"pypi","name":"orjson","versionSpec":">=3.11.5","scope":"runtime"},{"ecosystem":"pypi","name":"pillow","versionSpec":">=12.3.0","scope":"extra:matplotlib"},{"ecosystem":"pypi","name":"plotly","versionSpec":"<7.0,>=5.13","scope":"extra:plotly"},{"ecosystem":"pypi","name":"pydantic-core","versionSpec":">=2.35.0","scope":"runtime"},{"ecosystem":"pypi","name":"pygments","versionSpec":"<3.0.0,>=2.20.0","scope":"runtime"},{"ecosystem":"pypi","name":"python-dotenv","versionSpec":">=1.2.2","scope":"runtime"},{"ecosystem":"pypi","name":"python-multipart","versionSpec":">=0.0.31","scope":"runtime"},{"ecosystem":"pypi","name":"python-socketio","versionSpec":">=5.16.2","scope":"runtime"},{"ecosystem":"pypi","name":"pywebview","versionSpec":"<7,>=5.0.1","scope":"extra:native"},{"ecosystem":"pypi","name":"redis","versionSpec":">=4.0.0","scope":"extra:redis"},{"ecosystem":"pypi","name":"starlette","versionSpec":">=1.3.1","scope":"runtime"},{"ecosystem":"pypi","name":"tinycss2","versionSpec":"<2,>=1.4.0","scope":"runtime"},{"ecosystem":"pypi","name":"typing-extensions","versionSpec":">=4.0.0","scope":"runtime"},{"ecosystem":"pypi","name":"uvicorn","versionSpec":">=0.22.0","scope":"runtime"}],"advisories":[{"id":"c86c90a5-947f-4997-af5a-a128284c3b4b","url":"https://aisecwatch.com/issues/c86c90a5-947f-4997-af5a-a128284c3b4b","cveId":"CVE-2026-45554","title":"GHSA-pq7c-x8g4-rvp6: NiceGUI: Unauthenticated log-volume denial of service in dynamic resource routes","headline":null,"severity":"medium","publishedAt":"2026-05-18T20:22:07.000Z","affected":["nicegui@<= 3.11.1 (fixed: 3.12.0)"],"epssScore":0.006},{"id":"35806cf8-4ed5-45b3-8db2-9be7c3b3d3f4","url":"https://aisecwatch.com/issues/35806cf8-4ed5-45b3-8db2-9be7c3b3d3f4","cveId":"CVE-2026-45553","title":"GHSA-jfrm-rx66-g536: NiceGUI: Local file disclosure via Docutils file insertion in ui.restructured_text()","headline":null,"severity":"high","publishedAt":"2026-05-18T20:21:59.000Z","affected":["nicegui@<= 3.11.1 (fixed: 3.12.0)"],"epssScore":0.00432},{"id":"a566b09d-6c2e-4f9c-8ccb-ab9474cd05a8","url":"https://aisecwatch.com/issues/a566b09d-6c2e-4f9c-8ccb-ab9474cd05a8","cveId":"CVE-2026-39844","title":"GHSA-w8wv-vfpc-hw2w: NiceGUI: Upload filename sanitization bypass via backslashes allows path traversal on Windows","headline":null,"severity":"medium","publishedAt":"2026-04-08T15:04:13.000Z","affected":["nicegui@<= 3.9.0 (fixed: 3.10.0)"],"epssScore":0.00487}],"checkedAt":"2026-10-09T21:57:35.435Z"},"meta":{"advisoryMatching":"by package name; advisory records do not state an ecosystem"}}