PT-2020-16410 · Npm · Vega

Lowjheer

·

Published

2020-12-30

·

Updated

2021-01-06

·

CVE-2020-26296

CVSS v3.1

8.7

High

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions Vega versions prior to 5.17.3
Description Vega is a visualization grammar, a declarative format for creating, saving, and sharing interactive visualization designs. Vega is an npm package. In Vega, there is an XSS vulnerability in Vega expressions. Through a specially crafted Vega expression, an attacker could execute arbitrary javascript on a victim's machine.
Recommendations For versions prior to 5.17.3, update to version 5.17.3 to resolve the issue. As a temporary workaround, consider restricting the use of Vega expressions to minimize the risk of exploitation.

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-26296
GHSA-R2QC-W64X-6J54

Affected Products

Vega