CVE-2026-39844: 
Python vulnerability analysis and mitigation

Overview

CVE-2026-39844 is a path traversal vulnerability in NiceGUI's upload filename sanitization that allows arbitrary file writes on Windows systems. The flaw affects NiceGUI versions up to and including 3.9.0 (pip package nicegui), and was published on April 7–8, 2026. It was reported by researcher evnchn and remediated by falkoschindler in version 3.10.0. The CVSS v3.1 base score is 5.9 (Moderate) per the GitHub Advisory, though Feedly also references a score of 7.5 (High) under a different vector (Github Advisory, NiceGUI Release).

Technical details

The root cause (CWE-22: Path Traversal) lies in nicegui/elements/upload_files.py, where the prior sanitization used PurePosixPath(upload.filename or '').name to strip path components from uploaded filenames. Because PurePosixPath only recognizes forward slashes (/) as path separators, a filename containing backslashes (e.g., ..\..\secret\evil.txt) is returned unchanged. When this unsanitized filename is subsequently used in a Windows path operation such as Path('uploads') / file.name, the Windows Path object interprets the backslashes as directory separators, resolving the path outside the intended upload directory. The fix replaces the PurePosixPath approach with an explicit rsplit on both / and \, mirroring Django's multipart parser approach (Github Advisory, Patch Commit).

Impact

Successful exploitation enables unauthenticated remote attackers to write arbitrary files to any location accessible by the NiceGUI server process on Windows. This can lead to overwriting application files, placing malicious executables in known startup or PATH locations, and potentially achieving remote code execution. Data integrity is at high risk, while confidentiality and availability are not directly impacted by the vulnerability itself. Linux and macOS deployments are not affected, as those operating systems treat backslashes as literal filename characters (Github Advisory).

Exploitability

No public proof-of-concept exploit code or evidence of in-the-wild exploitation has been reported as of the time of disclosure (Github Advisory). The EPSS score is approximately 0.064% (20th percentile), indicating a low near-term exploitation probability. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. No threat actor attribution has been identified.

Exploitation steps

  1. Identify target: Locate a Windows-hosted NiceGUI application (version ≤ 3.9.0) that exposes a ui.upload component and uses file.name in path construction (a pattern shown in NiceGUI's bundled examples).
  2. Craft malicious filename: Prepare a file upload request with a filename containing backslash path traversal sequences, e.g., ..\..\..\Windows\System32\evil.exe or ..\..\app\main.py.
  3. Submit upload request: Send an HTTP multipart file upload request to the NiceGUI application's upload endpoint, supplying the crafted filename in the Content-Disposition header's filename field.
  4. Bypass sanitization: The server-side PurePosixPath(filename).name call returns the full backslash-containing string unchanged, as PurePosixPath does not treat \ as a separator.
  5. Trigger file write: When the application constructs the destination path (e.g., Path('uploads') / file.name), Windows resolves the backslashes as directory separators, writing the uploaded content to the attacker-controlled path outside the intended upload directory.
  6. Achieve objective: Depending on the target path, the attacker may overwrite application source files, place a web shell, or drop an executable in a startup location for subsequent code execution (Github Advisory, Patch Commit).

Indicators of compromise

  • Network: Multipart HTTP upload requests to NiceGUI endpoints where the Content-Disposition filename field contains backslash characters (e.g., filename="..\..\evil.exe").
  • File System: Unexpected files appearing outside the configured upload directory on Windows; new or modified .py, .exe, .bat, or .dll files in application directories or system paths that correspond to the NiceGUI server process's write permissions.
  • Logs: Web server or application logs showing upload requests with filenames containing \ or URL-encoded equivalents (%5C) combined with .. sequences; file write errors or access-denied events in directories outside the upload folder.
  • Process: Unexpected child processes spawned by the NiceGUI Python process following a file upload event, particularly if executables were written to startup or PATH locations.

Mitigation and workarounds

Upgrade NiceGUI to version 3.10.0 or later, which replaces the vulnerable PurePosixPath sanitization with an explicit rsplit on both / and \ characters, correctly stripping all path components on all platforms (NiceGUI Release, Patch Commit). As a temporary workaround for applications that cannot immediately upgrade, developers should avoid using file.name directly in path construction and instead apply platform-aware sanitization (e.g., stripping both / and \ before joining paths). Running NiceGUI on Linux or macOS eliminates this specific attack vector, as those systems treat backslashes as literal filename characters.

Additional resources


Source: This report was generated using AI

Related Python vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

GHSA-v2f8-6655-7grjCRITICAL10
  • Python logoPython
  • vibe-trading-ai
NoYesOct 02, 2026
CVE-2026-105782HIGH7.5
  • Python logoPython
  • scrapy
NoYesOct 06, 2026
GHSA-v853-p72q-4cfwHIGH7.5
  • Python logoPython
  • quart
NoYesOct 05, 2026
CVE-2026-105751MEDIUM6.9
  • Python logoPython
  • docling
NoYesOct 05, 2026
CVE-2026-105750MEDIUM5.9
  • Python logoPython
  • docling
NoYesOct 05, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management