Executive brief
Vega is a JavaScript visualization library used to create interactive data visualizations on web pages. A cross-site scripting (XSS) vulnerability in the vlSelectionTuples function allows attackers to inject and execute arbitrary JavaScript code through malicious Vega specifications, potentially compromising user sessions and stealing sensitive data from viewers of affected visualizations.
Technical details
The vlSelectionTuples function in Vega fails to properly sanitize attacker-controlled arguments passed to it, allowing an attacker to call the Function() constructor with arbitrary JavaScript code. The vulnerability exists in how the function processes the 'getter' parameter; an attacker can pass an array's constructor method (e.g., [].at.constructor) to gain access to the Function constructor and execute arbitrary code. This can be exploited by embedding a malicious Vega specification (JSON schema) with a crafted 'signals' section that triggers the XSS payload. No authentication is required—any user viewing a page embedding a malicious Vega visualization is at risk. The vulnerability has been patched in Vega v5.26.0 and vega-selections v5.4.2.
Affected products
- Vega Vega < 5.26.0
- Vega vega-selections < 5.4.2
Timeline
- 2025-02-14: disclosed: GHSA-mp7w-mhcv-673j published
- 2025-02-14: patched: Vega v5.26.0 and vega-selections v5.4.2 released