Vulnerabilities/

Vega Expression Language `scale` expression function Cross Site Scripting

Severity:
Medium

Description

The Vega scale expression function has the ability to call arbitrary functions with a single controlled argument. This can be exploited to escape the Vega expression sandbox in order to execute arbitrary JavaScript.

Recommendation

Update the vega-functions package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
vega-functions
Anything's wrong? Let us know Last updated on March 09, 2023

This issue is available in SmartScanner Professional

See Pricing