Vulnerabilities/

Vega allows Cross-site Scripting via the vlSelectionTuples function - vega-selections

Severity:
Medium

Description

The vlSelectionTuples function can be used to call JavaScript functions, leading to XSS.

Recommendation

Update the vega-selections package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
vega-selections
Anything's wrong? Let us know Last updated on February 14, 2025