Executive brief
NiceGUI apps are vulnerable to XSS which uses `ui.sub_pages` and render arbitrary user-provided links
Affected products
- PyPI nicegui
Junglewise Threat Intelligence
CVE-2026-21872 · Severity: low · CVSS 3.1 · Published 2026-07-07
Technologies: nicegui (PyPI). Vendors: PyPI.
NiceGUI apps are vulnerable to XSS which uses `ui.sub_pages` and render arbitrary user-provided links