VDB
Sign up
MEDIUM

GHSA-963h-3v39-3pqf

Vega vulnerable to Cross-site Scripting via RegExp.prototype[@@replace]

Quick fix

GHSA-963h-3v39-3pqf — vega: upgrade to the fixed version with the command below.

npm install vega@5.32.0

Details

## Impact

Users running Vega/Vega-lite JSON definitions could run unexpected JavaScript code when drawing graphs, unless the library is used with the `vega-interpreter`.

## Workarounds

- Use `vega` with [expression interpreter](https://vega.github.io/vega/usage/interpreter/) - Upgrade to a [newer Vega version](https://github.com/vega/vega/releases/tag/v5.32.0) (`5.32.0`)

### POC Summary

Calling `replace` with a `RegExp`-like pattern calls `RegExp.prototype[@@replace]`, which can then call an attacker-controlled `exec` function.

### POC Details

Consider the function call `replace('foo', {__proto__: /h/.constructor.prototype, global: false})`. Since `pattern` has `RegExp.prototype[@@replace]`, `pattern.exec('foo')` winds up being called.

The resulting malicious call looks like this: ``` replace(<string argument>, {__proto__: /h/.constructor.prototype, exec: <function>, global: false}) ```

Since functions cannot be returned from this, an attacker that wishes to escalate to XSS must abuse `event.view` to gain access to `eval`.

### Reproduction steps

``` {"$schema":"https://vega.github.io/schema/vega/v5.json","signals":[{"name":"a","on":[{"events":"body:mousemove{99999}","update":"replace('alert(1)',{__proto__:/h/.constructor.prototype,exec:event.view.eval,global:false})"}]}]} ```

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/vega
Introduced in: 0Fixed in: 5.32.0
Fixnpm install vega@5.32.0
npm/vega-functions
Introduced in: 0Fixed in: 5.17.0
Fixnpm install vega-functions@5.17.0

References