Логотип exploitDog
bind:CVE-2025-14896
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2025-14896

Количество 2

Количество 2

nvd логотип

CVE-2025-14896

около 2 месяцев назад

due to insufficient sanitazation in Vega’s `convert()` function when `safeMode` is enabled and the spec variable is an array. An attacker can craft a malicious Vega diagram specification that will allow them to send requests to any URL, including local file system paths, leading to exposure of sensitive information.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-5q5g-57mw-wmq6

около 2 месяцев назад

due to insufficient sanitazation in Vega’s `convert()` function when `safeMode` is enabled and the spec variable is an array. An attacker can craft a malicious Vega diagram specification that will allow them to send requests to any URL, including local file system paths, leading to exposure of sensitive information.

CVSS3: 7.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2025-14896

due to insufficient sanitazation in Vega’s `convert()` function when `safeMode` is enabled and the spec variable is an array. An attacker can craft a malicious Vega diagram specification that will allow them to send requests to any URL, including local file system paths, leading to exposure of sensitive information.

CVSS3: 7.5
0%
Низкий
около 2 месяцев назад
github логотип
GHSA-5q5g-57mw-wmq6

due to insufficient sanitazation in Vega’s `convert()` function when `safeMode` is enabled and the spec variable is an array. An attacker can craft a malicious Vega diagram specification that will allow them to send requests to any URL, including local file system paths, leading to exposure of sensitive information.

CVSS3: 7.5
0%
Низкий
около 2 месяцев назад

Уязвимостей на страницу