Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

4 advisories

Loading
Vega allows Cross-site Scripting via the vlSelectionTuples function Moderate
CVE-2025-25304 was published for vega (npm) Feb 14, 2025
FallingPineapples domoritz
Credited to FallingPineapples and domoritz
Vega Cross-Site Scripting (XSS) via event filter when not using CSP mode expressionInterpeter Moderate
CVE-2025-26619 was published for vega (npm) Mar 27, 2025
kprevas hydrosquall
domoritz mattijn lsh
Credited to kprevas, hydrosquall, domoritz, mattijn, and lsh
Vega vulnerable to Cross-site Scripting via RegExp.prototype[@@replace] Moderate
CVE-2025-27793 was published for vega (npm) Mar 27, 2025
FallingPineapples hydrosquall
domoritz
Credited to FallingPineapples, hydrosquall, and domoritz
nickcopi hydrosquall
domoritz jeramysoucy lsh
Credited to nickcopi, hydrosquall, domoritz, jeramysoucy, and lsh
ProTip! Advisories are also available from the GraphQL API