CVE-2026-21872
Estado: AnalizadaMedia (6.1)—
NiceGUI is a Python-based UI framework. From versions 2.22.0 to 3.4.1, an unsafe implementation in the click event listener used by ui.sub_pages, combined with attacker-controlled link rendering on the page, causes XSS when the user actively clicks on the link. This issue has been patched in version 3.5.0.
CVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
- Puntuación base: 6.1
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.27%
- Percentil entre todas las CVEs puntuadas: 18
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
CWE
- CWE-79
Referencias
JSON original (NVD)
Mostrar
{
"id": "CVE-2026-21872",
"cveTags": [],
"metrics": {
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2026-21872",
"role": "CISA Coordinator",
"options": [
{
"exploitation": "poc"
},
{
"automatable": "no"
},
{
"technicalImpact": "partial"
}
],
"version": "2.0.3",
"timestamp": "2026-01-08T15:12:53.988468Z"
}
}
],
"cvssMetricV31": [
{
"type": "Secondary",
"source": "security-advisories@github.com",
"cvssData": {
"scope": "CHANGED",
"version": "3.1",
"baseScore": 6.1,
"attackVector": "NETWORK",
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N",
"integrityImpact": "LOW",
"userInteraction": "REQUIRED",
"attackComplexity": "LOW",
"availabilityImpact": "NONE",
"privilegesRequired": "NONE",
"confidentialityImpact": "LOW"
},
"impactScore": 2.7,
"exploitabilityScore": 2.8
}
]
},
"affected": [
{
"source": "security-advisories@github.com",
"affectedData": [
{
"vendor": "zauberzeug",
"product": "nicegui",
"versions": [
{
"status": "affected",
"version": ">= 2.22.0, < 3.5.0"
}
]
}
]
}
],
"published": "2026-01-08T10:15:55.470",
"references": [
{
"url": "https://github.com/zauberzeug/nicegui/releases/tag/v3.5.0",
"tags": [
"Release Notes"
],
"source": "security-advisories@github.com"
},
{
"url": "https://github.com/zauberzeug/nicegui/security/advisories/GHSA-m7j5-rq9j-6jj9",
"tags": [
"Exploit",
"Vendor Advisory"
],
"source": "security-advisories@github.com"
}
],
"vulnStatus": "Analyzed",
"weaknesses": [
{
"type": "Secondary",
"source": "security-advisories@github.com",
"description": [
{
"lang": "en",
"value": "CWE-79"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "NiceGUI is a Python-based UI framework. From versions 2.22.0 to 3.4.1, an unsafe implementation in the click event listener used by ui.sub_pages, combined with attacker-controlled link rendering on the page, causes XSS when the user actively clicks on the link. This issue has been patched in version 3.5.0."
},
{
"lang": "es",
"value": "NiceGUI es un framework de interfaz de usuario (UI) basado en Python. Desde las versiones 2.22.0 hasta la 3.4.1, una implementación insegura en el oyente de eventos de clic utilizado por ui.sub_pages, combinada con la renderización de enlaces controlada por el atacante en la página, causa XSS cuando el usuario hace clic activamente en el enlace. Este problema ha sido parcheado en la versión 3.5.0."
}
],
"lastModified": "2026-06-17T10:19:03.980",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:zauberzeug:nicegui:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "37903F79-6269-4F0A-939A-36F3E3CC41B3",
"versionEndExcluding": "3.5.0",
"versionStartIncluding": "2.22.0"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "security-advisories@github.com"
}