Vega is a visualization grammar, a declarative format for creating, saving, and sharing interactive visualization designs. In `vega` 5.30.0 and lower and in `vega-functions` 5.15.0 and lower , it was possible to call JavaScript functions from the Vega expression language that were not meant to be supported. The issue is patched in `vega` `5.31.0` and `vega-functions` `5.16.0`. Some workarounds are available. Run `vega` without `vega.expressionInterpreter`. This mode is not the default as it is slower. Alternatively, using the interpreter described in CSP safe mode (Content Security Policy) prevents arbitrary Javascript from running, so users of this mode are not affected by this vulnerability.
History

Fri, 11 Apr 2025 16:30:00 +0000

Type Values Removed Values Added
First Time appeared Vega-functions Project
Vega-functions Project vega-functions
Vega Project
Vega Project vega
CPEs cpe:2.3:a:vega-functions_project:vega-functions:*:*:*:*:*:node.js:*:*
cpe:2.3:a:vega_project:vega:*:*:*:*:*:node.js:*:*
Vendors & Products Vega-functions Project
Vega-functions Project vega-functions
Vega Project
Vega Project vega
Metrics cvssV3_1

{'score': 6.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N'}


Thu, 27 Mar 2025 15:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 27 Mar 2025 14:00:00 +0000

Type Values Removed Values Added
Description Vega is a visualization grammar, a declarative format for creating, saving, and sharing interactive visualization designs. In `vega` 5.30.0 and lower and in `vega-functions` 5.15.0 and lower , it was possible to call JavaScript functions from the Vega expression language that were not meant to be supported. The issue is patched in `vega` `5.31.0` and `vega-functions` `5.16.0`. Some workarounds are available. Run `vega` without `vega.expressionInterpreter`. This mode is not the default as it is slower. Alternatively, using the interpreter described in CSP safe mode (Content Security Policy) prevents arbitrary Javascript from running, so users of this mode are not affected by this vulnerability.
Title Vega Cross-Site Scripting (XSS) via event filter when not using CSP mode `expressionInterpeter`
Weaknesses CWE-79
References
Metrics cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2025-03-27T14:21:44.479Z

Reserved: 2025-02-12T14:51:02.719Z

Link: CVE-2025-26619

cve-icon Vulnrichment

Updated: 2025-03-27T14:21:36.356Z

cve-icon NVD

Status : Analyzed

Published: 2025-03-27T14:15:52.987

Modified: 2025-04-11T16:12:33.110

Link: CVE-2025-26619

cve-icon Redhat

No data.