Loading
Create web-based user interfaces with Python. The nice way.
No LLM SDK, agent framework or MCP dependency in its latest release, and none among the tracked dependencies.
Advisories that name nicegui as affected. Advisory records do not state an ecosystem, so packages with the same name in other ecosystems also match. For a version-exact check of your own dependencies, use Stack Check.
| Advisory | Severity | Affected | Fixed in | Published |
|---|---|---|---|---|
| CVE-2026-45554GHSA-pq7c-x8g4-rvp6: NiceGUI: Unauthenticated log-volume denial of service in dynamic resource routes | Medium | <= 3.11.1 | 3.12.0 | 2026-05-18 |
| CVE-2026-45553GHSA-jfrm-rx66-g536: NiceGUI: Local file disclosure via Docutils file insertion in ui.restructured_text() | High | <= 3.11.1 | 3.12.0 | 2026-05-18 |
| CVE-2026-39844GHSA-w8wv-vfpc-hw2w: NiceGUI: Upload filename sanitization bypass via backslashes allows path traversal on Windows | Medium | <= 3.9.0 | 3.10.0 | 2026-04-08 |
As declared in PyPI metadata for version 3.18.0. Optional extras are listed with their extra name.
Among the packages in the registry; not every dependent on PyPI.