Junglewise Threat Intelligence

CVE-2025-66469: PYSEC-2026-1697 - NiceGUI Reflected XSS in ui.add_css, ui.add_scss, and ui.add_sass via Style Injection

CVE-2025-66469 · Severity: low · CVSS 3.1 · Published 2026-07-07

Technologies: nicegui (PyPI). Vendors: PyPI.

Executive brief

NiceGUI Reflected XSS in ui.add_css, ui.add_scss, and ui.add_sass via Style Injection

Affected products

  • PyPI nicegui

Related threats