Executive brief
NiceGUI is vulnerable to XSS via Unescaped URL in ui.navigate.history.push() / replace()
Affected products
- PyPI nicegui
Junglewise Threat Intelligence
CVE-2026-21871 · Severity: low · CVSS 3.1 · Published 2026-07-07
Technologies: nicegui (PyPI). Vendors: PyPI.
NiceGUI is vulnerable to XSS via Unescaped URL in ui.navigate.history.push() / replace()