Vulnerabilities/

Vega vulnerable to Cross-site Scripting via RegExp.prototype[@@replace]

Severity:
Medium

Description

Users running Vega/Vega-lite JSON definitions could run unexpected JavaScript code when drawing graphs, unless the library is used with the vega-interpreter.

Recommendation

Update the vega-functions package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
vega-functions
Anything's wrong? Let us know Last updated on March 27, 2025

This issue is available in SmartScanner Professional

See Pricing