CVE-2025-66645: 
Python vulnerability analysis and mitigation

Overview

CVE-2025-66645 is a path traversal vulnerability in NiceGUI's App.add_media_files() method that allows unauthenticated remote attackers to read arbitrary files on the server filesystem. It affects all versions of the nicegui Python package prior to 3.4.0. The vulnerability was discovered by security researcher Seungbin Yang (y4rvin), disclosed on December 8, 2025, and published to the GitHub Advisory Database on December 9, 2025. It carries a CVSS v3.1 base score of 7.5 (High) (Github Advisory).

Technical details

The root cause is CWE-22 (Path Traversal): the add_media_files(url_path, local_directory) method registers a FastAPI route using the {filename:path} parameter, which accepts full path strings including directory traversal sequences (../). The vulnerable code simply concatenates local_directory and the user-supplied filename without resolving symlinks or verifying that the resulting path remains within the intended directory — there is no call to .resolve() or is_relative_to() before serving the file. An attacker can supply URL-encoded traversal sequences (e.g., %2e%2e) to bypass naive client-side checks and reach files anywhere on the filesystem that the application process has read access to. The fix, applied in commit a1b89e2, resolves both paths and explicitly checks filepath.is_relative_to(local_dir) before serving (Github Advisory, Patch Commit).

Impact

Successful exploitation results in high confidentiality impact with no effect on integrity or availability. An unauthenticated attacker can read any file accessible to the NiceGUI server process, potentially exposing application source code, configuration files, credentials, API keys, secrets, and OS-level files such as /etc/passwd or /etc/hosts. Exposed credentials or API keys could enable lateral movement into connected systems or cloud environments, significantly amplifying the blast radius beyond the initial NiceGUI host (Github Advisory).

Exploitability

A working proof-of-concept was included in the original vulnerability report and is publicly documented in the GitHub Security Advisory. Exploitation requires no authentication, no privileges, and no user interaction — a single crafted HTTP GET request is sufficient. The EPSS score is approximately 0.755% (74th percentile), indicating a moderate probability of exploitation in the wild within 30 days. No threat actor attribution or confirmed in-the-wild exploitation has been reported, and the vulnerability is not listed in the CISA KEV catalog (Github Advisory).

Exploitation steps

  1. Reconnaissance: Identify internet-facing NiceGUI applications (versions < 3.4.0) that expose a media file endpoint via app.add_media_files(). This can be done using Shodan, Censys, or by inspecting the application's HTTP routes for path patterns like /<url_path>/{filename:path}.
  2. Identify the media URL path: Determine the URL prefix registered with add_media_files() (e.g., /media) by browsing the application or reviewing any exposed documentation/source.
  3. Craft a traversal payload: Construct a URL using URL-encoded dot sequences to traverse out of the media directory. For example, to read /etc/hosts from a server with the media path at /media:
    curl -v "http://<target>:8080/media/%2e%2e/%2e%2e/%2e%2e/etc/hosts"
  4. Retrieve sensitive files: Adjust the traversal depth and target path to read files of interest, such as /etc/passwd, application .env files, Python source files, or SSH private keys, depending on the server's directory structure and process permissions.
  5. Leverage exposed secrets: Use any discovered credentials, API keys, or configuration data for further access to connected systems or cloud services (Github Advisory).

Indicators of compromise

  • Network: HTTP GET requests to NiceGUI media endpoints (e.g., /media/) containing URL-encoded traversal sequences such as %2e%2e, %2f, or literal ../ in the path; requests targeting known sensitive paths like /etc/passwd, /etc/hosts, or .env files.
  • Logs: Web server or application access logs showing 200 OK responses to requests with traversal patterns in the URL path; repeated requests to the media endpoint with varying traversal depths from a single source IP.
  • File System: No direct file system artifacts are created by read-only exploitation; however, evidence of reconnaissance may appear in application logs if verbose logging is enabled.
  • Process: No unusual child processes are expected, as exploitation is limited to file reads via the existing application process (Github Advisory).

Mitigation and workarounds

Upgrade to NiceGUI version 3.4.0 or later, which resolves the vulnerability by resolving both the base directory and the requested file path, then verifying the result with filepath.is_relative_to(local_dir) before serving the file. No configuration-based workaround is available for older versions; the only safe remediation is upgrading the package via pip install --upgrade nicegui. As an interim measure, operators can restrict network access to NiceGUI media endpoints using a reverse proxy or firewall rules to limit exposure to trusted clients (Github Advisory, Patch Commit).

Community reactions

The vulnerability was reported by Seungbin Yang, a cybersecurity student, and remediated by NiceGUI maintainers (evnchn as remediation developer, falkoschindler as reviewer) promptly after disclosure on December 8, 2025. The advisory was noted by automated vulnerability tracking services including CIRCL Vulnerability Lookup and INCIBE-CERT. No significant broader media coverage or notable researcher commentary beyond the original advisory has been identified (Github Advisory).

Additional resources


Source: This report was generated using AI

Related Python vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

GHSA-v2f8-6655-7grjCRITICAL10
  • Python logoPython
  • vibe-trading-ai
NoYesOct 02, 2026
CVE-2026-105782HIGH7.5
  • Python logoPython
  • scrapy
NoYesOct 06, 2026
GHSA-v853-p72q-4cfwHIGH7.5
  • Python logoPython
  • quart
NoYesOct 05, 2026
CVE-2026-105751MEDIUM6.9
  • Python logoPython
  • docling
NoYesOct 05, 2026
CVE-2026-105750MEDIUM5.9
  • Python logoPython
  • docling
NoYesOct 05, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management