Home
HIGH: 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:NHIGH: 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N Any version before *
affected
Description
due to insufficient sanitazation in Vega’s `convert()` function when `safeMode` is enabled and the spec variable is an array. An attacker can craft a malicious Vega diagram specification that will allow them to send requests to any URL, including local file system paths, leading to exposure of sensitive information.
Problem types
Files or Directories Accessible to External Parties
Product status
Credits
Catalin Iovita (Snyk Security Research)
References
github.com/...ommit/f31093cd8a0a1d6999c43d560f62d1e82d59c77e
Data based on CVE®. Copyright © 1999-2025, The MITRE Corporation. All rights reserved.