CVE-2026-21871: 
Python vulnerability analysis and mitigation

Overview

CVE-2026-21871 is a DOM-based Cross-Site Scripting (XSS) vulnerability in NiceGUI, a Python-based web UI framework. It affects NiceGUI versions 2.13.0 through 3.4.1, where attacker-controlled strings passed into ui.navigate.history.push() or ui.navigate.history.replace() are embedded into generated JavaScript without proper escaping, allowing arbitrary JavaScript execution in the victim's browser. The vulnerability was published on January 8, 2026, and patched in version 3.5.0. It carries a CVSS v3.1 base score of 6.1 (Medium) (Github Advisory, NiceGUI Advisory).

Technical details

The root cause is improper neutralization of user-controllable input before it is placed in JavaScript output (CWE-79). NiceGUI's ui.navigate.history.push(url) and ui.navigate.history.replace(url) functions are documented as wrappers for the browser History API; however, the URL argument is embedded directly into generated JavaScript without escaping. An attacker who controls input passed to these functions (e.g., via URL path segments, query parameters such as next=..., or form values) can inject characters like quotes and statement terminators to break out of the JavaScript string context and execute arbitrary code. A public proof-of-concept is included in the security advisory, demonstrating exploitation via a crafted path such as /%22);alert(document.domain);// (Github Advisory, NiceGUI Advisory).

Impact

Successful exploitation allows an attacker to execute arbitrary JavaScript in the victim's browser, enabling session cookie theft, user session hijacking, unauthorized actions performed on behalf of the victim, phishing UI injection, and redirection to malicious sites. The vulnerability has a changed scope, meaning the impact extends beyond the vulnerable component to the user's browser context. Availability is not directly impacted, but confidentiality and integrity are both affected at a low level per the CVSS assessment. Only applications that forward untrusted input into the affected navigation functions are at risk (Github Advisory).

Exploitability

A proof-of-concept exploit is publicly available in the GitHub security advisory, demonstrating the attack with a simple NiceGUI application. There is no evidence of in-the-wild exploitation at this time, and no threat actor attribution has been reported. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The EPSS score is approximately 0.009% (1st percentile), indicating a low near-term probability of exploitation (Github Advisory).

Exploitation steps

  1. Identify a vulnerable application: Find a NiceGUI application (versions 2.13.0–3.4.1) that accepts user-controlled input (e.g., URL path segments, query parameters, or form values) and passes it to ui.navigate.history.push() or ui.navigate.history.replace().
  2. Craft a malicious payload: Construct a URL or input value containing JavaScript injection characters, such as ");alert(document.domain);//, which will break out of the JavaScript string context when embedded by the vulnerable function.
  3. Deliver the payload: Send the victim a crafted link that navigates to the vulnerable page with the malicious path or parameter, e.g., http://target-app/%22);alert(document.domain);//.
  4. Trigger the vulnerable code path: Induce the victim to interact with the page (e.g., click a button or load a page) that causes the application to call ui.navigate.history.push(payload) with the attacker-controlled value.
  5. Achieve JavaScript execution: The injected payload executes in the victim's browser, enabling cookie theft, session hijacking, or further client-side attacks (NiceGUI Advisory, Github Advisory).

Indicators of compromise

  • Network: Unusual HTTP requests to NiceGUI application endpoints containing URL-encoded JavaScript payloads (e.g., %22, %29, alert, document.cookie) in path segments or query parameters.
  • Logs: Web server or application access logs showing requests with suspicious characters such as ");, //, or JavaScript function names (e.g., alert, fetch, document.cookie) in URL paths or query strings.
  • Browser/Client-Side: Unexpected JavaScript dialogs (e.g., alert) appearing in users' browsers when navigating the application; reports from users of unexpected redirects or UI changes.
  • Application Behavior: Anomalous outbound requests from victim browsers to attacker-controlled domains, potentially visible in network monitoring or browser developer tools (NiceGUI Advisory).

Mitigation and workarounds

Upgrade NiceGUI to version 3.5.0 or later, which includes a fix that properly escapes URL arguments before embedding them into generated JavaScript (NiceGUI v3.5.0 Release). If immediate patching is not possible, implement strict input validation and URL encoding for any user-supplied input before passing it to ui.navigate.history.push() or ui.navigate.history.replace(). Review application code to identify all call sites of these functions and ensure only trusted, validated URLs are used as arguments. Applications that do not pass untrusted input into these functions are not affected (Github Advisory).

Community reactions

The vulnerability was reported by security researchers xx-mikusan-xx and evnchn, with remediation handled by NiceGUI maintainer falkoschindler. The fix was released promptly on the same day as disclosure (January 8, 2026) as part of NiceGUI v3.5.0, which also addressed two other XSS advisories in the same release. Coverage has been limited to automated vulnerability tracking platforms and a brief mention on Bluesky (NiceGUI v3.5.0 Release, Github Advisory).

Additional resources


Source: This report was generated using AI

Related Python vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

GHSA-v2f8-6655-7grjCRITICAL10
  • Python logoPython
  • vibe-trading-ai
NoYesOct 02, 2026
CVE-2026-105782HIGH7.5
  • Python logoPython
  • scrapy
NoYesOct 06, 2026
GHSA-v853-p72q-4cfwHIGH7.5
  • Python logoPython
  • quart
NoYesOct 05, 2026
CVE-2026-105751MEDIUM6.9
  • Python logoPython
  • docling
NoYesOct 05, 2026
CVE-2026-105750MEDIUM5.9
  • Python logoPython
  • docling
NoYesOct 05, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management