Vulnerability library
Security checkMarch 13, 2023

Vega has Cross-site Scripting vulnerability in `lassoAppend` function - vega

Understand the exposure, see the recommended fix, and check whether your own website has related weaknesses.

Medium severitynpmvega

Check your website

Find this and other vulnerabilities with a free scan.

Your scan runs on your computer. No account required.

Description

Vega’s lassoAppend function: lassoAppend accepts 3 arguments and internally invokes push function on the 1st argument specifying array consisting of 2nd and 3rd arguments as push call argument. The type of the 1st argument is supposed to be an array, but it’s not enforced.

Recommendation

Update the vega package to the latest compatible version. Followings are version details:

  • Affected version(s): < 5.23.0
  • Patched version(s): 5.23.0

References

Could your website be exposed too?

SmartScanner can check your website for Vega has Cross-site Scripting vulnerability in `lassoAppend` function - vega and gives you actionable findings to investigate.

Start a free scan

Related Issues

See something that needs correcting? Let us knowUpdated March 13, 2023