Lucene search

K
osvGoogleOSV:GHSA-R2QC-W64X-6J54
HistoryDec 30, 2020 - 11:09 p.m.

XSS in Vega

2020-12-3023:09:21
Google
osv.dev
14

0.001 Low

EPSS

Percentile

41.3%

Vega is a visualization grammar, a declarative format for creating, saving, and sharing interactive visualization designs. Vega in an npm package.
In Vega before version 5.17.3 there is an XSS vulnerability in Vega expressions. Through a specially crafted Vega expression, an attacker could
execute arbitrary javascript on a victim’s machine.

This is fixed in version 5.17.3

CPENameOperatorVersion
vegalt5.17.3

0.001 Low

EPSS

Percentile

41.3%