CVE-2025-66645 is a directory traversal vulnerability affecting NiceGUI versions 3.3.1 and below, allowing remote attackers to read arbitrary files on the server filesystem. With a CVSS score of 7.5 (HIGH), this vulnerability is easily exploitable over the network without user interaction, leading to a high impact on confidentiality. While no public exploits, Metasploit modules, or Nuclei templates are currently available, and there is minimal community discussion or media coverage, the vulnerability has a high FAUCET Risk Score of 85/100. Organizations using affected NiceGUI versions should upgrade to version 3.4.0 immediately to mitigate this risk.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 3.4.0CPE matchmatch criteria | cpe:2.3:a:zauberzeug:nicegui:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.