VDB
Sign up
MEDIUM

GHSA-cp47-r258-q626

Vega vulnerable to arbitrary code execution when clicking href links

Quick fix

GHSA-cp47-r258-q626 — vega: upgrade to the fixed version with the command below.

npm install vega@5.4.1

Details

Vega is vulnerable to arbitrary code execution when clicking href links. Versions 5.4.1 and 4.5.1 contain a patch.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/vega
Introduced in: 5.0.0Fixed in: 5.4.1
Fixnpm install vega@5.4.1
npm/vega
Introduced in: 0Fixed in: 4.5.1
Fixnpm install vega@4.5.1

References