Intel

AIKIDO-2025-10006

nicegui is vulnerable to Improper Authentication

Improper AuthenticationCVE-2025-21618

75

High Risk

This Affects:

pythonnicegui
1.3.0 - 2.9.0
Fixed in 2.9.1

TL;DR

Affected versions of this package are affected by a broken access control due to inadequate isolation of session states across different browsers. When a user logs into one browser, they are automatically authenticated in all other browsers on the same device, including incognito mode, without needing to log in again. It may lead to unauthorized access, particularly when using shared or public devices.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

nicegui is vulnerable to Improper Authentication in versions 1.3.0 - 2.9.0.

How to fix this

Upgrade the NiceGUI library to the patch version.