CVE-2026-25732: 
Python vulnerability analysis and mitigation

Overview

CVE-2026-25732 is a path traversal vulnerability (CWE-22) in NiceGUI, a Python-based UI framework, affecting all versions up to and including 3.6.1. The flaw exists in the FileUpload.name property, which exposes client-supplied filename metadata without sanitization, enabling attackers to write files outside intended directories when developers use the common pattern UPLOAD_DIR / e.file.name. It was published on February 5, 2026, and patched in version 3.7.0. The vulnerability carries a CVSS v3.1 base score of 7.5 (High) (GitHub Advisory).

Technical details

The root cause is the absence of path validation in the save() methods of both SmallFileUpload and LargeFileUpload classes in nicegui/elements/upload_files.py (lines 79–82 and 110–115). The save() method directly accepts any path — including those with ../ sequences or absolute paths — without resolving or constraining the target to a safe base directory. When application developers follow the common community pattern save_path = UPLOAD_DIR / e.file.name and call await e.file.save(save_path), an attacker supplying a filename like ../../../app.py causes the file to be written outside the intended upload directory. Exploitation requires no authentication and no special privileges — only the ability to submit an HTTP multipart file upload request with a crafted filename (GitHub Advisory, NiceGUI Source).

Impact

Successful exploitation allows an unauthenticated attacker to write arbitrary files to any location writable by the application process. The most severe consequence is remote code execution achieved by overwriting Python application source files (e.g., app.py) with malicious code that executes upon application restart. Additional impacts include overwriting configuration files to alter application behavior, writing SSH authorized keys or systemd units for persistent access, and corrupting critical files to cause denial of service. The CVSS score reflects a high integrity impact with no direct confidentiality or availability impact in the base score, though real-world exploitation can achieve all three (GitHub Advisory).

Exploitability

The vulnerability is trivially exploitable without authentication, requiring only the ability to send an HTTP multipart upload request with a malicious filename. A public proof-of-concept exploit is available in the official security advisory and a separate PoC repository has been published on GitHub (PoC Repo). An Exploit-DB entry (52534) has also been published. The EPSS score is approximately 1.47% (81st percentile), indicating elevated exploitation probability relative to most CVEs. As of the advisory date, there is no confirmed evidence of in-the-wild exploitation, and the vulnerability is not listed in the CISA KEV catalog (GitHub Advisory).

Exploitation steps

  1. Reconnaissance: Identify a publicly accessible NiceGUI application (version ≤ 3.6.1) that exposes a file upload interface via ui.upload(). Tools like Shodan or Censys can be used to find internet-facing instances.
  2. Discover the upload endpoint: Fetch the application's main page and parse the HTML to extract the upload URL pattern /_nicegui/client/<client_id>/upload/<element_id> using a regex or browser developer tools.
  3. Craft a malicious filename: Prepare a file payload (e.g., a Python script containing a reverse shell or command execution stub) and name it with path traversal sequences such as ../vulnerable_app.py or ../../../etc/cron.d/backdoor.
  4. Submit the upload: Send an HTTP POST multipart request to the discovered upload endpoint with the malicious filename:
    import requests
    s = requests.Session()
    payload = 'from nicegui import ui\nimport subprocess\n@ui.page("/")\ndef index(): ui.label(subprocess.check_output(["id"], text=True))\nui.run(port=8080, reload=False)'
    s.post('http://<target>:8080/_nicegui/client/<id>/upload/<elem_id>',
           files={'file': ('../vulnerable_app.py', payload, 'text/x-python')})
  5. Trigger execution: Wait for or induce an application restart (e.g., via a separate DoS or by exploiting a known restart mechanism). Upon restart, the overwritten Python file executes the injected code.
  6. Achieve objective: Access the application to confirm code execution (e.g., the injected id command output is rendered on the page), then proceed with lateral movement, data exfiltration, or persistence establishment (GitHub Advisory).

Indicators of compromise

  • Network: Unexpected HTTP POST requests to /_nicegui/client/<id>/upload/<id> endpoints containing multipart filenames with ../ sequences; outbound connections from the application server to unknown external IPs following an upload event.
  • File System: Unexpected modification timestamps on Python application files (e.g., app.py, main.py) or configuration files in the application directory; new or modified files in parent directories of the intended upload folder; presence of SSH keys, cron jobs, or systemd unit files not previously present.
  • Logs: Web server or application access logs showing POST requests to upload endpoints with encoded or literal ../ in the Content-Disposition: filename field; application error logs showing unexpected file write operations outside the upload directory.
  • Process: Unusual child processes spawned by the Python/NiceGUI process after a restart (e.g., bash, curl, wget, nc); unexpected network listeners or outbound connections initiated by the application process (GitHub Advisory).

Mitigation and workarounds

Upgrade NiceGUI to version 3.7.0 or later, which introduces a _sanitize_filename() function that strips all path components from uploaded filenames before use (GitHub Advisory). For applications that cannot be immediately upgraded, developers should sanitize filenames in their upload handlers using safe_name = Path(e.file.name).name before constructing save paths, or use generated UUIDs as filenames instead of user-supplied names. Additionally, validate that resolved file paths remain within the intended upload directory using Path(target).resolve().is_relative_to(base_dir), and apply strict OS-level file permissions to limit what the application process can write to. Conduct a code review of all ui.upload() implementations to identify any use of e.file.name directly in path construction (NiceGUI Source).

Community reactions

The vulnerability was reported by researcher k14uz, with remediation developed by NiceGUI maintainer falkoschindler and analysis by evnchn. The advisory notes that the pattern is a prevalent "security footgun" because community documentation and examples naturally encourage developers to use e.file.name directly, making the vulnerability widespread in production deployments. No significant broader media coverage or notable social media reactions beyond the GitHub advisory and standard vulnerability database entries have been identified (GitHub Advisory).

Additional resources


Source: This report was generated using AI

Related Python vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

GHSA-v2f8-6655-7grjCRITICAL10
  • Python logoPython
  • vibe-trading-ai
NoYesOct 02, 2026
CVE-2026-105782HIGH7.5
  • Python logoPython
  • scrapy
NoYesOct 06, 2026
GHSA-v853-p72q-4cfwHIGH7.5
  • Python logoPython
  • quart
NoYesOct 05, 2026
CVE-2026-105751MEDIUM6.9
  • Python logoPython
  • docling
NoYesOct 05, 2026
CVE-2026-105750MEDIUM5.9
  • Python logoPython
  • docling
NoYesOct 05, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management