CVE-2026-45553Disclosure

LOWCVSS 7.5 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

NiceGUI is a Python-based UI framework. Prior to version 3.12.0, ui.restructured_text() renders reStructuredText server-side with Docutils without disabling file insertion directives. When a NiceGUI application passes attacker-controlled content to ui.restructured_text(), an attacker can use standard Docutils directives (include, csv-table with :file:, raw with :file:) to read local files readable by the NiceGUI server process. Applications that only pass trusted static strings to ui.restructured_text() are not affected. This issue has been patched in version 3.12.0.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-200

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • 1 mentions across 1 observed day

What's happening

  • Disclosure: 1 classified signal
  • 1 total mentions across 1 day

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-05-14: 105-14
Signal classification1 categories
Disclosure
1100.0%
Referenced assets1 URL
By indicator
Full discourse1 post
  • Rohit Prasanth@h3ri0s
    Disclosure

    Got my first CVE — (CVE-2026-45553) Reported a High Severity vulnerability in NiceGUI. Huge thanks to @teambi0s mentors and the NiceGUI maintainers for the quick response and smooth disclosure. https://github.com/zauberzeug/nicegui/security/advisories/GHSA-jfrm-rx66-g536

    Post summary

    User announces their first CVE (CVE-2026-45553), a high severity flaw discovered in NiceGUI, thanking mentors and maintainers for a swift and smooth disclosure process.

    330100333
    36 followersView on X

Explore more