Description
Applications meeting 2 conditions are at risk of arbitrary JavaScript code execution, even if “safe mode” expressionInterpreter is used.
- Use
vegain an application that attachesvegalibrary and avega.Viewinstance similar to the Vega Editor to the globalwindow2.
Recommendation
Update the vega-expression package to the latest compatible version. Followings are version details:
Affected version(s): **< 5.2.1 >= 6.0.0, < 6.1.0** Patched version(s): **5.2.1 6.1.0**
References
Could your website be exposed too?
SmartScanner can check your website for Vega Cross-Site Scripting (XSS) via expressions abusing toString calls in environments using the VEGA_DEBUG global varia - vega-expression and gives you actionable findings to investigate.
Start a free scanRelated Issues
- Vega Cross-Site Scripting (XSS) via expressions abusing toString calls in environments using the VEGA_DEBUG global varia - CVE-2025-59840
- Vega Cross-Site Scripting (XSS) via expressions abusing toString calls in environments using the VEGA_DEBUG global varia - vega-interpreter - CVE-2025-59840
- Vega XSS via expression abusing vlSelectionTuples function array map calls in environments with satisfactory function ga - CVE-2025-65110
- Vega Cross-Site Scripting (XSS) via event filter when not using CSP mode expressionInterpeter - CVE-2025-26619


