HIGH8.7
GHSA-r2qc-w64x-6j54
XSS in Vega
Quick fix
GHSA-r2qc-w64x-6j54 — vega: upgrade to the fixed version with the command below.
npm install vega@5.17.3Details
Vega is a visualization grammar, a declarative format for creating, saving, and sharing interactive visualization designs. Vega in an npm package. In Vega before version 5.17.3 there is an XSS vulnerability in Vega expressions. Through a specially crafted Vega expression, an attacker could execute arbitrary javascript on a victim's machine.
This is fixed in version 5.17.3
Are you affected?
Enter the version of the package you're using.
Affected packages
References
- https://github.com/vega/vega/security/advisories/GHSA-r2qc-w64x-6j54[WEB]
- https://nvd.nist.gov/vuln/detail/CVE-2020-26296[ADVISORY]
- https://github.com/vega/vega/issues/3018[WEB]
- https://github.com/vega/vega/pull/3019[WEB]
- https://github.com/vega/vega/releases/tag/v5.17.3[WEB]
- https://www.npmjs.com/package/vega[WEB]