Junglewise Threat Intelligence

CVE-2026-21871: PYSEC-2026-1698 - NiceGUI is vulnerable to XSS via Unescaped URL in ui.navigate.history.push() / replace()

CVE-2026-21871 · Severity: low · CVSS 3.1 · Published 2026-07-07

Technologies: nicegui (PyPI). Vendors: PyPI.

Executive brief

NiceGUI is vulnerable to XSS via Unescaped URL in ui.navigate.history.push() / replace()

Affected products

  • PyPI nicegui

Related threats