Executive brief
Vega is a popular declarative language for creating interactive visualizations. A Cross-Site Scripting (XSS) vulnerability in the event filter mechanism allows attackers to inject and execute arbitrary JavaScript when users interact with visualizations, potentially stealing data or session credentials. This affects versions that do not use Content Security Policy (CSP) safe mode, which is not the default configuration.
Technical details
The vulnerability is a Cross-Site Scripting (CWE-79) flaw in Vega's event filter mechanism when not using CSP mode expression interpreter. The root cause is insufficient input sanitization in the expression language parser, which allows attackers to call JavaScript functions that were not meant to be supported through crafted event filters. An attacker can inject malicious code via the "filter" parameter in event handlers (e.g., mousedown), which executes arbitrary JavaScript in the victim's browser when they interact with the visualization. The attack requires user interaction (clicking on a mark) but no authentication. Patches are available in vega 5.31.0 and vega-functions 5.16.0; users can also mitigate by running vega without the expression interpreter or by using CSP safe mode.
Affected products
- Vega Vega 5.30.0 and lower
- Vega vega-functions 5.15.0 and lower
Timeline
- 2025-03-27: disclosed: Vulnerability published as GHSA-rcw3-wmx7-cphr and CVE-2025-26619
- 2025-03-27: patched: Patched in vega 5.31.0 and vega-functions 5.16.0