nicegui@1.4.10 vulnerabilities

Create web-based user interfaces with Python. The nice way.

Direct Vulnerabilities

Known vulnerabilities in the nicegui package. This does not include vulnerabilities belonging to this package’s dependencies.

Automatically find and fix vulnerabilities affecting your projects. Snyk scans for vulnerabilities and provides fixes for free.
Fix for free
Vulnerability Vulnerable Version
  • H
Relative Path Traversal

nicegui is a Create web-based user interfaces with Python. The nice way.

Affected versions of this package are vulnerable to Relative Path Traversal due to the handling of resource files under the /_nicegui/{__version__}/resources/{key}/{path:path} route. An attacker can read any file on the backend filesystem which the web server has access to by accessing the NiceUI leaflet website.

How to fix Relative Path Traversal?

Upgrade nicegui to version 1.4.21 or higher.

[1.4.6,1.4.21)