Vulnerabilities/

Vega allows Cross-site Scripting via the vlSelectionTuples function (GHSA-mp7w-mhcv-673j)

Severity:
Medium

Description

The vlSelectionTuples function can be used to call JavaScript functions, leading to XSS.

Recommendation

Update the vega-selections package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
vega-selections
Anything's wrong? Let us know Last updated on February 14, 2025

This issue is available in SmartScanner Professional

See Pricing