
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-21872 is a Cross-Site Scripting (XSS) vulnerability in NiceGUI, a Python-based UI framework, affecting versions 2.22.0 through 3.4.1. The flaw exists in the ui.sub_pages component's click event listener, which — when combined with attacker-controlled link rendering — allows malicious JavaScript to execute in a victim's browser upon clicking a crafted link. It was disclosed and patched on January 8, 2026, with the fix released in version 3.5.0. The vulnerability carries a CVSS v3.1 base score of 6.1 (Medium) (Github Advisory, NiceGUI Advisory).
The root cause (CWE-79) lies in sub_pages_router.py, where the _handle_navigate method constructs a JavaScript string using an f-string that directly interpolates self.current_path without sanitization, surrounding it only with double-quotes. When a user clicks any <a href> link on a page using ui.sub_pages, the JavaScript click listener in sub_pages.js emits a sub_pages_navigate event with the raw href value. An attacker who can control link content on the page (e.g., via ui.markdown rendering user-supplied Markdown) can craft a URL such as /"+alert(1)+" to break out of the string context and inject arbitrary JavaScript, which is then executed via client.run_javascript(). Exploitation requires no privileges and no special configuration beyond the application using ui.sub_pages alongside a component that renders attacker-controlled links (Github Advisory, NiceGUI Advisory).
Successful exploitation allows an attacker to execute arbitrary JavaScript in the victim's browser within the application's security scope (scope changed). This can lead to theft of session tokens, credentials, and other sensitive data accessible to the browser, as well as unauthorized actions performed on behalf of the victim. Availability is not impacted, and the overall severity is moderated by the requirement for user interaction (clicking the malicious link). Any NiceGUI application using ui.sub_pages alongside components that render user-supplied links — a common pattern with ui.markdown — is affected (Github Advisory).
A proof-of-concept (PoC) exploit is publicly available in the GitHub security advisory, demonstrating both a minimal direct case and a more realistic attacker-controlled Markdown input scenario. There is no evidence of in-the-wild exploitation at this time, and the vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The EPSS score is approximately 0.009% (1st percentile), indicating a low near-term exploitation probability. No threat actor attribution has been reported (Github Advisory, NiceGUI Advisory).
ui.sub_pages and renders user-controlled link content, such as via ui.markdown bound to user-supplied input.href that breaks out of the JavaScript string context, e.g., [XSS LINK](/"+alert(document.domain)+"). For a direct PoC, the link target /"+alert(1)+" is sufficient.ui.markdown component (e.g., a textarea bound to shared app storage).sub_pages.js emits sub_pages_navigate with the raw href._handle_navigate in sub_pages_router.py interpolates the unsanitized path into an f-string passed to client.run_javascript(), executing the injected JavaScript in the victim's browser — enabling session token theft, credential harvesting, or further malicious actions (Github Advisory, NiceGUI Advisory).sub_pages_navigate events with href values containing characters such as ", +, or JavaScript function names (e.g., alert, fetch, document.cookie).run_javascript calls; unexpected history.pushState calls with malformed path values.ui.sub_pages (Github Advisory).Upgrade NiceGUI to version 3.5.0 or later, which patches this vulnerability by sanitizing the path value before interpolation into JavaScript strings (NiceGUI v3.5.0 Release). For organizations unable to upgrade immediately, implement Content Security Policy (CSP) headers to restrict inline script execution, and restrict or sanitize user-controlled input rendered as links on pages using ui.sub_pages. Additionally, avoid binding untrusted user input directly to ui.markdown or other link-rendering components in applications that use ui.sub_pages (Github Advisory).
The vulnerability was reported by security researchers evnchn and xx-mikusan-xx, with remediation review by NiceGUI maintainer falkoschindler, reflecting a responsible disclosure process within the project's community. The advisory notes that the impact is considered low due to the mandatory user click requirement, and the CVSS scoring was reviewed manually after an initial AI-assisted assessment. No significant broader media coverage or notable external researcher commentary has been identified beyond the GitHub advisory and standard vulnerability aggregator coverage (NiceGUI Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."