Skip to content

Vega vulnerable to arbitrary code execution when clicking href links

Moderate severity GitHub Reviewed Published Mar 2, 2023 in vega/vega • Updated Mar 2, 2023

Package

npm vega (npm)

Affected versions

>= 5.0.0, < 5.4.1
< 4.5.1

Patched versions

5.4.1
4.5.1

Description

Vega is vulnerable to arbitrary code execution when clicking href links. Versions 5.4.1 and 4.5.1 contain a patch.

References

@domoritz domoritz published to vega/vega Mar 2, 2023
Published to the GitHub Advisory Database Mar 2, 2023
Reviewed Mar 2, 2023
Last updated Mar 2, 2023

Severity

Moderate

EPSS score

Weaknesses

No CWEs

CVE ID

No known CVE

GHSA ID

GHSA-cp47-r258-q626

Source code

Loading Checking history
See something to contribute? Suggest improvements for this vulnerability.