Junglewise Threat Intelligence

CVE-2026-21872: PYSEC-2026-1701 - NiceGUI apps are vulnerable to XSS which uses `ui.sub_pages` and render arbitrary user-provided links

CVE-2026-21872 · Severity: low · CVSS 3.1 · Published 2026-07-07

Technologies: nicegui (PyPI). Vendors: PyPI.

Executive brief

NiceGUI apps are vulnerable to XSS which uses `ui.sub_pages` and render arbitrary user-provided links

Affected products

  • PyPI nicegui

Related threats