Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

6 advisories

Loading
`vega-functions` vulnerable to Cross-site Scripting via `setdata` function High
CVE-2025-66648 was published for vega-functions (npm) Jan 5, 2026
nikolaybabiy Credited to nikolaybabiy, hydrosquall, and domoritz hydrosquall hydrosquall
domoritz domoritz
nickcopi Credited to nickcopi, hydrosquall, and domoritz hydrosquall hydrosquall
domoritz domoritz
nickcopi Credited to nickcopi, hydrosquall, domoritz, jeramysoucy, lsh, and kachkaev hydrosquall hydrosquall
domoritz domoritz jeramysoucy jeramysoucy lsh lsh kachkaev kachkaev
Vega vulnerable to Cross-site Scripting via RegExp.prototype[@@replace] Moderate
CVE-2025-27793 was published for vega (npm) Mar 27, 2025
FallingPineapples Credited to FallingPineapples, hydrosquall, and domoritz hydrosquall hydrosquall
domoritz domoritz
Vega Cross-Site Scripting (XSS) via event filter when not using CSP mode expressionInterpeter Moderate
CVE-2025-26619 was published for vega (npm) Mar 27, 2025
kprevas Credited to kprevas, hydrosquall, domoritz, mattijn, and lsh hydrosquall hydrosquall
domoritz domoritz mattijn mattijn lsh lsh
Vega allows Cross-site Scripting via the vlSelectionTuples function Moderate
CVE-2025-25304 was published for vega (npm) Feb 14, 2025
FallingPineapples Credited to FallingPineapples and domoritz domoritz domoritz
ProTip! Advisories are also available from the GraphQL API