CVE-2025-27793

MEDIUM

Vega <5.32.0/5.17.0 - Code Injection

Title source: llm
STIX 2.1

Description

Vega is a visualization grammar, a declarative format for creating, saving, and sharing interactive visualization designs. In Vega prior to version 5.32.0, corresponding to vega-functions prior to version 5.17.0, users running Vega/Vega-lite JSON definitions could run unexpected JavaScript code when drawing graphs, unless the library was used with the `vega-interpreter`. Vega version 5.32.0 and vega-functions version 5.17.0 fix the issue. As a workaround, use `vega` with expression interpreter.

Scores

CVSS v4 5.3
EPSS 0.0023
EPSS Percentile 45.8%
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-79 CWE-87
Status published
Products (3)
npm/vega 0 - 5.32.0npm
npm/vega-functions 0 - 5.17.0npm
vega/vega < 5.32.0
Published Mar 27, 2025
Tracked Since Feb 18, 2026