CVE-2025-66645: NiceGUI has a path traversal in app.add_media_files() allows arbitrary file read
(updated )
A directory traversal vulnerability in NiceGUI’s App.add_media_files() allows a remote attacker to read arbitrary files on the server filesystem.
References
Code Behaviors & Features
Detect and mitigate CVE-2025-66645 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →