CVE-2026-27156Disclosure(zauberzeug / nicegui)

LOWCVSS 6.1 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

NiceGUI is a Python-based UI framework. Prior to version 3.8.0, several NiceGUI APIs that execute methods on client-side elements (`Element.run_method()`, `AgGrid.run_grid_method()`, `EChart.run_chart_method()`, and others) use an `eval()` fallback in the JavaScript-side `runMethod()` function. When user-controlled input is passed as the method name, an attacker can inject arbitrary JavaScript that executes in the victim's browser. Additionally, `Element.run_method()` and `Element.get_computed_prop()` used string interpolation instead of `json.dumps()` for the method/property name, allowing quote injection to break out of the intended string context. Version 3.8.0 contains a fix.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-79

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • nicegui

Threat summary

  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 3 signals
  • Disclosure: 3 classified signals
  • Peaked 1d ago at 2 mentions (2026-02-24); latest day: 1
  • 3 total mentions across 2 days

Affected systems

Vendors
Products
nicegui

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-02-24: 2Mentions · 2026-02-25: 1Technical Details · 2026-02-24: 2Technical Details · 2026-02-25: 102-2402-25
Signal classification1 categories
Disclosure
3100.0%
Referenced assets5 URLs
Classification over time
DateTotalLabels
2026-02-242
Disclosure2
2026-02-251
Disclosure1
Full discourse3 posts
  • CVE@CVEnew
    Disclosure

    CVE-2026-27156 NiceGUI is a Python-based UI framework. Prior to version 3.8.0, several NiceGUI APIs that execute methods on client-side elements (`http://Element.run_method()`, `http://AgGrid.run… https://www.cve.org/CVERecord?id=CVE-2026-27156

    Post summary

    The text announces CVE‑2026‑27156 affecting NiceGUI before v3.8.0, noting that certain APIs can execute client‑side methods, but provides no PoC, exploit, or patch details.

    00000140
    56.6K followersView on X
  • cvereports@_cvereports
    Disclosure

    CVE-2026-27156: NiceGUI CVE-2026-27156: When F-Strings Build Bridges to Hell A critical Cross-Site Scripting (XSS) vulnerability in NiceGUI allows attackers to execute arbitrary JavaScript by injecting malicious payloads into method names. The flaw st... https://cvereports.com/reports/CVE-2026-27156

    Post summary

    The post announces a critical XSS flaw in NiceGUI that enables attackers to execute arbitrary JavaScript by injecting malicious payloads into method names.

    0000039
    31 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-27156 NiceGUI JavaScript Injection Vulnerability via Method Name Parameter https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-27156

    Post summary

    A JavaScript injection vulnerability in NiceGUI via the method name parameter has been identified as CVE-2026-27156, with details available on Vulmon.

    0000035
    4.0K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appzauberzeugnicegui---

Explore more