cvedb.io
CVE-2026-39844
MEDIUM · CVSS 5.9
EPSS exploitation probability: 0%
Published 2026-04-08T21:16:59.883 · Last modified 2026-06-17T10:42:41.267

Summary

NiceGUI is a Python-based UI framework. Prior to 3.10.0, Since PurePosixPath only recognizes forward slashes (/) as path separators, an attacker can bypass this sanitization on Windows by using backslashes (\) in the upload filename. Applications that construct file paths using file.name (a pattern demonstrated in NiceGUI's bundled examples) are vulnerable to arbitrary file write on Windows. This vulnerability is fixed in 3.10.0.

Affected products

zauberzeug — nicegui

Does this affect you?

Add your gear to cvedb and we'll alert you only when zauberzeug ships something exploited.

Check my exposure →

References

This product uses data from the NVD API but is not endorsed or certified by the NVD. Informational only; not professional security advice.