MEDIUM
GHSA-cp47-r258-q626
Vega vulnerable to arbitrary code execution when clicking href links
Quick fix
GHSA-cp47-r258-q626 — vega: upgrade to the fixed version with the command below.
npm install vega@5.4.1Details
Vega is vulnerable to arbitrary code execution when clicking href links. Versions 5.4.1 and 4.5.1 contain a patch.
Are you affected?
Enter the version of the package you're using.
Affected packages
References
- https://github.com/vega/vega/security/advisories/GHSA-cp47-r258-q626[WEB]
- https://github.com/vega/vega/pull/1892[WEB]
- https://github.com/vega/vega/commit/692327013eb4dd5adec0c47a620181af1b135e2a[WEB]
- https://github.com/vega/vega[PACKAGE]
- https://github.com/vega/vega/commits/v4.5.1[WEB]
- https://github.com/vega/vega/commits/v5.4.1[WEB]