CVE-2026-21871 | zauberzeug nicegui up to 3.4.x cross site scripting (GHSA-7grm-h62g-5m97)
A vulnerability described as problematic has been identified in zauberzeug nicegui up to 3.4.x. Affected by this issue is the function ui.navigate.history.push/ui.navigate.history.replace. The manipulation results in cross site scripting.
This vulnerability is cataloged as CVE-2026-21871. The attack may be launched remotely. There is no exploit available.
Upgrading the affected component is recommended.