Vulnerabilities/

Vega Cross-Site Scripting (XSS) via expressions abusing toString calls in environments using the VEGA_DEBUG global varia

Severity:
High

Description

Applications meeting 2 conditions are at risk of arbitrary JavaScript code execution, even if “safe mode” expressionInterpreter is used.

  1. Use vega in an application that attaches vega library and a vega.View instance similar to the Vega Editor to the global window 2.

Recommendation

Update the vega package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
vega
Anything's wrong? Let us know Last updated on November 14, 2025