Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2025-27793


Vega is a visualization grammar, a declarative format for creating, saving, and sharing interactive visualization designs. In Vega prior to version 5.32.0, corresponding to vega-functions prior to version 5.17.0, users running Vega/Vega-lite JSON definitions could run unexpected JavaScript code when drawing graphs, unless the library was used with the `vega-interpreter`. Vega version 5.32.0 and vega-functions version 5.17.0 fix the issue. As a workaround, use `vega` with expression interpreter.


Published

2025-03-27T14:15:54.060

Last Modified

2025-03-27T16:45:12.210

Status

Awaiting Analysis

Source

[email protected]

Severity

-

Weaknesses
  • Type: Secondary
    CWE-79
    CWE-87

Affected Vendors & Products

-


References