CVE-2026-21872

NiceGUI is a Python-based UI framework. From versions 2.22.0 to 3.4.1, an unsafe implementation in the click event listener used by ui.sub_pages, combined with attacker-controlled link rendering on the page, causes XSS when the user actively clicks on the link. This issue has been patched in version 3.5.0.
Configurations

No configuration.

History

08 Jan 2026, 10:15

Type Values Removed Values Added
New CVE

Information

Published : 2026-01-08 10:15

Updated : 2026-01-08 18:08


NVD link : CVE-2026-21872

Mitre link : CVE-2026-21872

CVE.ORG link : CVE-2026-21872


JSON object : View

Products Affected

No product.

CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')