Description
The Vega scale expression function has the ability to call arbitrary functions with a single controlled argument. This can be exploited to escape the Vega expression sandbox in order to execute arbitrary JavaScript.
Recommendation
Update the vega package to the latest compatible version. Followings are version details:
- Affected version(s): < 5.23.0
- Patched version(s): 5.23.0
References
Could your website be exposed too?
SmartScanner can check your website for Vega Expression Language `scale` expression function Cross Site Scripting - vega and gives you actionable findings to investigate.
Start a free scanRelated Issues
- Vega Expression Language `scale` expression function Cross Site Scripting - CVE-2023-26486
- Vega has Cross-site Scripting vulnerability in `lassoAppend` function - CVE-2023-26487
- Vega has Cross-site Scripting vulnerability in `lassoAppend` function - vega - CVE-2023-26487
- `vega-functions` vulnerable to Cross-site Scripting via `setdata` function - CVE-2025-66648


