Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
Tools/GitHubGitHub/jmehta10/cve-2025-66470
ReconnaissanceVulnerability ScannersWeb Vulnerability ScannersExploitationWeb Application ExploitationInformation GatheringPenetration Testing
GitHubjmehta10/cve-2025-66470

CVE-2025-66470

A fast, simple scanner for detecting CVE-2025-66470 - XSS vulnerability in NiceGUI's ui.interactive_image component.

View Repository
21129 months agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

NiceGUI XSS Scanner - CVE-2025-66470

Python License CVE

📸 Screenshot

Scanner Screenshot

** A fast, simple scanner for detecting CVE-2025-66470 - XSS vulnerability in NiceGUI's ui.interactive_image component. **

🔍 Vulnerability Details

FieldValue
CVECVE-2025-66470
GHSAGHSA-2m4f-cg75-76w2
Componentui.interactive_image
AffectedNiceGUI ≤ 3.3.1
FixedNiceGUI 3.4.0+
TypeStored/Reflected XSS

Root Cause

The ui.interactive_image component renders SVG content using Vue's v-html directive without sanitization, allowing XSS via <foreignObject> tag.

Vulnerable Code:

<g v-html="content"></g>

📦 Files

FileDescription
nicegui_scanner.pySimple scanner - Clean one-line output per target
nicegui_xss_scanner.pyFull scanner - Detailed analysis with reports
targets.txtSample targets file for batch scanning

🚀 Quick Start

Installation

git clone https://github.com/yourusername/nicegui-xss-scanner.git
cd nicegui-xss-scanner
pip install requests

Usage

Single Target:

python nicegui_scanner.py http://target.com/

Batch Scan (from file):

python nicegui_scanner.py -l targets.txt

Full Analysis:

python nicegui_xss_scanner.py http://target.com/

📋 Options

usage: nicegui_scanner.py [-h] [-l LIST] [--timeout TIMEOUT] [target]

NiceGUI XSS Scanner - CVE-2025-66470

positional arguments:
  target                Target URL

options:
  -h, --help            Show help message
  -l, --list LIST       File with URLs (one per line)
  --timeout TIMEOUT     Request timeout (default: 10)

📊 Output Examples

Simple Scanner

╔══════════════════════════════════════════════════════════════╗
║  NiceGUI XSS Scanner - CVE-2025-66470                        ║
╚══════════════════════════════════════════════════════════════╝

[*] Scanning 3 target(s)...

──────────────────────────────────────────────────────────────────────
[1/3] http://192.168.1.10:8080/... 🚨 CONFIRMED (v2.1.0)
[2/3] http://192.168.1.20:5000/... ⚠ VULN_VER (v3.3.0)
[3/3] http://example.com/...       ✓ NOT_NICEGUI
──────────────────────────────────────────────────────────────────────

SUMMARY:
  Total scanned:  3
  XSS CONFIRMED:  1

✓ Saved: nicegui_CONFIRMED_174530.txt

Status Legend

StatusMeaning
🚨 CONFIRMEDXSS vulnerability confirmed (all 3 checks passed)
⚠ VULN_VERVulnerable version detected, needs manual testing
✓ NOT_NICEGUINot a NiceGUI application

🧪 3-Check Confirmation System

For XSS to be marked as CONFIRMED, all 3 checks must pass:

  1. CHECK 1: Payload marker is reflected in response
  2. CHECK 2: Dangerous HTML patterns (`` to embed HTML:
<foreignObject>
  <body xmlns="http://www.w3.org/1999/xhtml">
    
  </body>
</foreignObject>

📄 targets.txt Format

# Comments start with #
http://target1.com/
http://target2.com:8080/
https://target3.com/login

🔧 Requirements

  • Python 3.8+
  • requests library
pip install requests

📚 References

  • GitHub Advisory - GHSA-2m4f-cg75-76w2
  • NVD - CVE-2025-66470
  • Fix Commit

⚠️ Disclaimer

This tool is for authorized security testing only. Use responsibly and only on systems you have permission to test.

📜 License

MIT License - See LICENSE for details.

Download Tool