Skip to content

Vega expression XSS

Low
jheer published GHSA-r2qc-w64x-6j54 Dec 30, 2020

Package

npm vega (npm)

Affected versions

<5.17.3

Patched versions

5.17.3

Description

Impact

An XSS vulnerability in Vega expressions.

Patches

Upgrade to 5.17.3

References

#3018

Severity

Low

CVE ID

CVE-2020-26296

Weaknesses

No CWEs