Executive brief
NiceGUI apps which use `ui.sub_pages` vulnerable to zero-click XSS
Affected products
- PyPI nicegui
Junglewise Threat Intelligence
CVE-2026-21873 · Severity: low · CVSS 3.1 · Published 2026-07-07
Technologies: nicegui (PyPI). Vendors: PyPI.
NiceGUI apps which use `ui.sub_pages` vulnerable to zero-click XSS