top of page
perceptive_background_267k.jpg

NiceGUI is a Python-based UI framework. Prior to version 3.12.0, ui.restructured_text() renders reStructuredText server-side with Docutils without disabling fil…

Published:

1 juni 2026 om 22:00:00

Alert date:

2 juni 2026 om 18:03:09

Source:

nvd.nist.gov

Click to open the original link from this advisory

Web Technologies, Supply Chain & Dependencies

CVE-2026-45553 affects NiceGUI, a Python-based UI framework, in versions prior to 3.12.0. The vulnerability exists in the ui.restructured_text() function which renders reStructuredText server-side using Docutils without properly disabling file insertion directives. Attackers can exploit this by passing malicious content to ui.restructured_text() and using standard Docutils directives (include, csv-table with :file:, raw with :file:) to read local files accessible to the NiceGUI server process. Applications that only use trusted static strings with ui.restructured_text() are not affected. The vulnerability has been patched in version 3.12.0.

Technical details

Mitigation steps:

Affected products:

NiceGUI

Related links:

Related CVE's:

Related threat actors:

IOC's:

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Deze website toont informatie afkomstig van externe bronnen; Perceptive aanvaardt geen verantwoordelijkheid voor de juistheid, volledigheid of actualiteit van deze informatie.

bottom of page