PT-2025-13187 · Vega+2 · Vega+2
Kprevas
·
Publicado
2025-03-27
·
Atualizado
2025-03-28
·
CVE-2025-26619
CVSS v3.1
6.1
Média
| Vetor | AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
vega versions 5.30.0 and lower
vega-functions versions 5.15.0 and lower
Description
The issue allows calling JavaScript functions from the Vega expression language that were not meant to be supported. This can be mitigated by running
vega without vega.expressionInterpreter, although this mode is slower. Alternatively, using the interpreter described in CSP safe mode (Content Security Policy) prevents arbitrary Javascript from running.Recommendations
For vega versions 5.30.0 and lower, update to version 5.31.0 to resolve the issue.
For vega-functions versions 5.15.0 and lower, update to version 5.16.0 to resolve the issue.
As a temporary workaround, consider running
vega without vega.expressionInterpreter to minimize the risk of exploitation.
Restrict access to the vega.expressionInterpreter to minimize the risk of exploitation.Exploit
Correção
XSS
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Debian
Vega
Vega-Functions