Executive brief
Vega is a popular JavaScript library for creating interactive data visualizations. A cross-site scripting (XSS) vulnerability in Vega expressions allows an attacker to inject malicious code that executes in a victim's browser, potentially leading to theft of sensitive data or hijacking of user sessions.
Technical details
A cross-site scripting (CWE-79) vulnerability exists in Vega expression evaluation, where specially crafted expressions can execute arbitrary JavaScript in the victim's browser context. The vulnerability affects all versions prior to 5.17.3 and requires network access and user interaction (opening a malicious visualization) to exploit, but does not require authentication. An attacker can craft a malicious Vega specification that, when processed and rendered, executes arbitrary code with the privileges of the victim's session. The vulnerability is fixed in version 5.17.3.
Affected products
- Vega Vega before 5.17.3
Timeline
- 2020-12-30: disclosed
- 2020-12-30: patched