Description
Applications meeting these two conditions are at risk of arbitrary JavaScript code execution, even if “safe mode” expressionInterpreter is used.
- Use
vegain an application that attaches bothvegalibrary and avega.Viewinstance similar to the Vega Editor to the globalwindow, or has any other satisfactory function gadgets in the global scope 2.
Recommendation
Update the vega-selections package to the latest compatible version. Followings are version details:
Affected version(s): **>= 6.0.0, < 6.1.2 < 5.6.3** Patched version(s): **6.1.2 5.6.3**
References
Could your website be exposed too?
SmartScanner can check your website for Vega XSS via expression abusing vlSelectionTuples function array map calls in environments with satisfactory function ga and gives you actionable findings to investigate.
Start a free scanRelated Issues
- Vega Cross-Site Scripting (XSS) via expressions abusing toString calls in environments using the VEGA_DEBUG global varia - vega-expression - CVE-2025-59840
- Vega Cross-Site Scripting (XSS) via expressions abusing toString calls in environments using the VEGA_DEBUG global varia - vega-interpreter - CVE-2025-59840
- Vega Cross-Site Scripting (XSS) via expressions abusing toString calls in environments using the VEGA_DEBUG global varia - CVE-2025-59840
- Vega allows Cross-site Scripting via the vlSelectionTuples function - vega-selections - CVE-2025-25304


