
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-21871 is a DOM-based Cross-Site Scripting (XSS) vulnerability in NiceGUI, a Python-based web UI framework. It affects NiceGUI versions 2.13.0 through 3.4.1, where attacker-controlled strings passed into ui.navigate.history.push() or ui.navigate.history.replace() are embedded into generated JavaScript without proper escaping, allowing arbitrary JavaScript execution in the victim's browser. The vulnerability was published on January 8, 2026, and patched in version 3.5.0. It carries a CVSS v3.1 base score of 6.1 (Medium) (Github Advisory, NiceGUI Advisory).
The root cause is improper neutralization of user-controllable input before it is placed in JavaScript output (CWE-79). NiceGUI's ui.navigate.history.push(url) and ui.navigate.history.replace(url) functions are documented as wrappers for the browser History API; however, the URL argument is embedded directly into generated JavaScript without escaping. An attacker who controls input passed to these functions (e.g., via URL path segments, query parameters such as next=..., or form values) can inject characters like quotes and statement terminators to break out of the JavaScript string context and execute arbitrary code. A public proof-of-concept is included in the security advisory, demonstrating exploitation via a crafted path such as /%22);alert(document.domain);// (Github Advisory, NiceGUI Advisory).
Successful exploitation allows an attacker to execute arbitrary JavaScript in the victim's browser, enabling session cookie theft, user session hijacking, unauthorized actions performed on behalf of the victim, phishing UI injection, and redirection to malicious sites. The vulnerability has a changed scope, meaning the impact extends beyond the vulnerable component to the user's browser context. Availability is not directly impacted, but confidentiality and integrity are both affected at a low level per the CVSS assessment. Only applications that forward untrusted input into the affected navigation functions are at risk (Github Advisory).
A proof-of-concept exploit is publicly available in the GitHub security advisory, demonstrating the attack with a simple NiceGUI application. There is no evidence of in-the-wild exploitation at this time, and no threat actor attribution has been reported. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The EPSS score is approximately 0.009% (1st percentile), indicating a low near-term probability of exploitation (Github Advisory).
ui.navigate.history.push() or ui.navigate.history.replace().");alert(document.domain);//, which will break out of the JavaScript string context when embedded by the vulnerable function.http://target-app/%22);alert(document.domain);//.ui.navigate.history.push(payload) with the attacker-controlled value.%22, %29, alert, document.cookie) in path segments or query parameters.");, //, or JavaScript function names (e.g., alert, fetch, document.cookie) in URL paths or query strings.alert) appearing in users' browsers when navigating the application; reports from users of unexpected redirects or UI changes.Upgrade NiceGUI to version 3.5.0 or later, which includes a fix that properly escapes URL arguments before embedding them into generated JavaScript (NiceGUI v3.5.0 Release). If immediate patching is not possible, implement strict input validation and URL encoding for any user-supplied input before passing it to ui.navigate.history.push() or ui.navigate.history.replace(). Review application code to identify all call sites of these functions and ensure only trusted, validated URLs are used as arguments. Applications that do not pass untrusted input into these functions are not affected (Github Advisory).
The vulnerability was reported by security researchers xx-mikusan-xx and evnchn, with remediation handled by NiceGUI maintainer falkoschindler. The fix was released promptly on the same day as disclosure (January 8, 2026) as part of NiceGUI v3.5.0, which also addressed two other XSS advisories in the same release. Coverage has been limited to automated vulnerability tracking platforms and a brief mention on Bluesky (NiceGUI v3.5.0 Release, Github Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."