CVE-2020-26296
XSS in Vega
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
Vega is a visualization grammar, a declarative format for creating, saving, and sharing interactive visualization designs. Vega in an npm package. In Vega before version 5.17.3 there is an XSS vulnerability in Vega expressions. Through a specially crafted Vega expression, an attacker could execute arbitrary javascript on a victim's machine. This is fixed in version 5.17.3
Vega es una gramática de visualización, un formato declarativo para crear, guardar y compartir diseños de visualización interactivos. Vega en un paquete npm. En Vega versiones anteriores a 5.17.3, se presenta una vulnerabilidad de tipo XSS en las expresiones de Vega. Mediante una expresión Vega especialmente diseñada, un atacante podría ejecutar javascript arbitrario en la máquina de una víctima. Esto es corregido en la versión 5.17.3
CVSS Scores
SSVC
- Decision:-
Timeline
- 2020-10-01 CVE Reserved
- 2020-12-30 CVE Published
- 2024-08-04 CVE Updated
- 2025-03-30 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CAPEC
References (5)
URL | Tag | Source |
---|---|---|
https://github.com/vega/vega/issues/3018 | Third Party Advisory | |
https://github.com/vega/vega/pull/3019 | Third Party Advisory | |
https://github.com/vega/vega/releases/tag/v5.17.3 | Release Notes | |
https://github.com/vega/vega/security/advisories/GHSA-r2qc-w64x-6j54 | Third Party Advisory | |
https://www.npmjs.com/package/vega | Third Party Advisory |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Vega Project Search vendor "Vega Project" | Vega Search vendor "Vega Project" for product "Vega" | < 5.17.3 Search vendor "Vega Project" for product "Vega" and version " < 5.17.3" | node.js |
Affected
|