CVE-2026-21872: 
Python vulnerability analysis and mitigation

Overview

CVE-2026-21872 is a Cross-Site Scripting (XSS) vulnerability in NiceGUI, a Python-based UI framework, affecting versions 2.22.0 through 3.4.1. The flaw exists in the ui.sub_pages component's click event listener, which — when combined with attacker-controlled link rendering — allows malicious JavaScript to execute in a victim's browser upon clicking a crafted link. It was disclosed and patched on January 8, 2026, with the fix released in version 3.5.0. The vulnerability carries a CVSS v3.1 base score of 6.1 (Medium) (Github Advisory, NiceGUI Advisory).

Technical details

The root cause (CWE-79) lies in sub_pages_router.py, where the _handle_navigate method constructs a JavaScript string using an f-string that directly interpolates self.current_path without sanitization, surrounding it only with double-quotes. When a user clicks any <a href> link on a page using ui.sub_pages, the JavaScript click listener in sub_pages.js emits a sub_pages_navigate event with the raw href value. An attacker who can control link content on the page (e.g., via ui.markdown rendering user-supplied Markdown) can craft a URL such as /"+alert(1)+" to break out of the string context and inject arbitrary JavaScript, which is then executed via client.run_javascript(). Exploitation requires no privileges and no special configuration beyond the application using ui.sub_pages alongside a component that renders attacker-controlled links (Github Advisory, NiceGUI Advisory).

Impact

Successful exploitation allows an attacker to execute arbitrary JavaScript in the victim's browser within the application's security scope (scope changed). This can lead to theft of session tokens, credentials, and other sensitive data accessible to the browser, as well as unauthorized actions performed on behalf of the victim. Availability is not impacted, and the overall severity is moderated by the requirement for user interaction (clicking the malicious link). Any NiceGUI application using ui.sub_pages alongside components that render user-supplied links — a common pattern with ui.markdown — is affected (Github Advisory).

Exploitability

A proof-of-concept (PoC) exploit is publicly available in the GitHub security advisory, demonstrating both a minimal direct case and a more realistic attacker-controlled Markdown input scenario. There is no evidence of in-the-wild exploitation at this time, and the vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The EPSS score is approximately 0.009% (1st percentile), indicating a low near-term exploitation probability. No threat actor attribution has been reported (Github Advisory, NiceGUI Advisory).

Exploitation steps

  1. Identify a vulnerable target: Find a NiceGUI application (versions 2.22.0–3.4.1) that uses ui.sub_pages and renders user-controlled link content, such as via ui.markdown bound to user-supplied input.
  2. Craft a malicious link payload: Prepare a Markdown link with a specially crafted href that breaks out of the JavaScript string context, e.g., [XSS LINK](/"+alert(document.domain)+"). For a direct PoC, the link target /"+alert(1)+" is sufficient.
  3. Inject the payload: Submit the malicious Markdown content through any user-input mechanism that feeds into a ui.markdown component (e.g., a textarea bound to shared app storage).
  4. Trigger execution: Wait for or socially engineer a victim user to click the rendered malicious link on the page. The click event listener in sub_pages.js emits sub_pages_navigate with the raw href.
  5. Achieve JavaScript execution: _handle_navigate in sub_pages_router.py interpolates the unsanitized path into an f-string passed to client.run_javascript(), executing the injected JavaScript in the victim's browser — enabling session token theft, credential harvesting, or further malicious actions (Github Advisory, NiceGUI Advisory).

Indicators of compromise

  • Network: Unexpected outbound requests from a user's browser to attacker-controlled domains following interaction with a NiceGUI application page; unusual WebSocket messages containing JavaScript payloads.
  • Logs: Application logs showing sub_pages_navigate events with href values containing characters such as ", +, or JavaScript function names (e.g., alert, fetch, document.cookie).
  • Browser/Client-Side: Browser developer tools showing execution of unexpected JavaScript originating from run_javascript calls; unexpected history.pushState calls with malformed path values.
  • Application Behavior: Reports from users of unexpected pop-ups, redirects, or unauthorized actions after clicking links within a NiceGUI app using ui.sub_pages (Github Advisory).

Mitigation and workarounds

Upgrade NiceGUI to version 3.5.0 or later, which patches this vulnerability by sanitizing the path value before interpolation into JavaScript strings (NiceGUI v3.5.0 Release). For organizations unable to upgrade immediately, implement Content Security Policy (CSP) headers to restrict inline script execution, and restrict or sanitize user-controlled input rendered as links on pages using ui.sub_pages. Additionally, avoid binding untrusted user input directly to ui.markdown or other link-rendering components in applications that use ui.sub_pages (Github Advisory).

Community reactions

The vulnerability was reported by security researchers evnchn and xx-mikusan-xx, with remediation review by NiceGUI maintainer falkoschindler, reflecting a responsible disclosure process within the project's community. The advisory notes that the impact is considered low due to the mandatory user click requirement, and the CVSS scoring was reviewed manually after an initial AI-assisted assessment. No significant broader media coverage or notable external researcher commentary has been identified beyond the GitHub advisory and standard vulnerability aggregator coverage (NiceGUI Advisory).

Additional resources


Source: This report was generated using AI

Related Python vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

GHSA-v2f8-6655-7grjCRITICAL10
  • Python logoPython
  • vibe-trading-ai
NoYesOct 02, 2026
CVE-2026-105782HIGH7.5
  • Python logoPython
  • scrapy
NoYesOct 06, 2026
GHSA-v853-p72q-4cfwHIGH7.5
  • Python logoPython
  • quart
NoYesOct 05, 2026
CVE-2026-105751MEDIUM6.9
  • Python logoPython
  • docling
NoYesOct 05, 2026
CVE-2026-105750MEDIUM5.9
  • Python logoPython
  • docling
NoYesOct 05, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management