Junglewise Threat Intelligence

Vega arbitrary code execution via href links

Severity: info · Published 2023-03-02

Executive brief

Vega is a data visualization library used to create interactive charts and graphs. A vulnerability allows attackers to execute arbitrary code when a user clicks on href links in visualizations, potentially compromising user systems and data. This could be exploited through malicious Vega specifications embedded in web pages or applications.

Technical details

The vulnerability is an arbitrary code execution flaw triggered when clicking href links in Vega visualizations. The root cause involves improper handling or validation of href attributes, allowing injection of executable code. The attack vector is user interaction—a victim must click a malicious href link embedded in a Vega visualization. No authentication is required, but the attacker must craft a malicious Vega specification or modify an existing one. Successful exploitation allows arbitrary code execution in the user's browser context. Patches were released in versions 5.4.1 and 4.5.1.

Affected products

  • Vega Vega all versions before 4.5.1; 5.0.0 through 5.4.0

Timeline

  • 2023-03-02: disclosed

References