CVE-2025-53354
Last modified
CVE-2025-53354 is a medium-severity vulnerability rated 6.1/10 on the CVSS scale. NiceGUI is a Python-based UI framework. Versions 2.24.2 and below are at risk for Cross-Site Scripting (XSS) when developers render unescaped user input into the DOM using ui.html(). EPSS estimates a 0.18% chance of exploitation in the next 30 days.
Description
NiceGUI is a Python-based UI framework. Versions 2.24.2 and below are at risk for Cross-Site Scripting (XSS) when developers render unescaped user input into the DOM using ui.html(). NiceGUI did not enforce HTML or JavaScript sanitization, so applications that directly combine components like ui.input() with ui.html() or ui.chat_message with HTML content without escaping may allow attackers to execute arbitrary JavaScript in the user’s browser. Applications that do not pass untrusted input into ui.html() are not affected. This issue is fixed in version 3.0.0.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Weakness Enumeration
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2025-53354?
How severe is CVE-2025-53354?
How do I fix CVE-2025-53354?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2025
- CVE-2025-53348Missing Authorization vulnerability in Laborator Kalium kali…5.3
- CVE-2025-53349Improper Neutralization of Input During Web Page Generation …7.1
- CVE-2025-5335A maliciously crafted binary file when downloaded could lead…7.8
- CVE-2025-53350Improper Neutralization of Input During Web Page Generation …7.1
- CVE-2025-53351Improper Neutralization of Input During Web Page Generation …7.1
- CVE-2025-53352Improper Neutralization of Input During Web Page Generation …7.1
- CVE-2025-53355MCP Server Kubernetes is an MCP Server that can connect to a…7.5
- CVE-2025-53357GLPI, which stands for Gestionnaire Libre de Parc Informatiq…5.4
- CVE-2025-53358kotaemon is an open-source RAG-based tool for document compr…6.5
- CVE-2025-53359ethereum is a common ethereum structs for Rust. Prior to eth…6.9
- CVE-2025-5336The Click to Chat plugin for WordPress is vulnerable to Stor…6.4
- CVE-2025-53360pluginsGLPI's Database Inventory Plugin "manages" the Teclib…4.3
Are you affected by CVE-2025-53354?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
