2025-12-09 00:11:14
GitHub_M
PUBLISHED
NiceGUI is a Python-based UI framework. Versions 3.3.1 and below are subject to a XSS vulnerability through the ui.interactive_image component of NiceGUI. The component renders SVG content using Vues v-html directive without any sanitization. This allows attackers to inject malicious HTML or JavaScript via the SVG