Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-5q5g-57mw-wmq6

Опубликовано: 18 дек. 2025
Источник: github
Github: Не прошло ревью
CVSS4: 8.7
CVSS3: 7.5

Описание

due to insufficient sanitazation in Vega’s convert() function when safeMode is enabled and the spec variable is an array. An attacker can craft a malicious Vega diagram specification that will allow them to send requests to any URL, including local file system paths, leading to exposure of sensitive information.

due to insufficient sanitazation in Vega’s convert() function when safeMode is enabled and the spec variable is an array. An attacker can craft a malicious Vega diagram specification that will allow them to send requests to any URL, including local file system paths, leading to exposure of sensitive information.

EPSS

Процентиль: 13%
0.00044
Низкий

8.7 High

CVSS4

7.5 High

CVSS3

Дефекты

CWE-552

Связанные уязвимости

CVSS3: 7.5
nvd
около 2 месяцев назад

due to insufficient sanitazation in Vega’s `convert()` function when `safeMode` is enabled and the spec variable is an array. An attacker can craft a malicious Vega diagram specification that will allow them to send requests to any URL, including local file system paths, leading to exposure of sensitive information.

EPSS

Процентиль: 13%
0.00044
Низкий

8.7 High

CVSS4

7.5 High

CVSS3

Дефекты

CWE-552