{"id":"CVE-2020-26296","aliases":["GHSA-r2qc-w64x-6j54"],"url":"https://o3.security/vulnerability/CVE-2020-26296","summary":"XSS in Vega","details":"Vega is a visualization grammar, a declarative format for creating, saving, and sharing interactive visualization designs. Vega in an npm package. In Vega before version 5.17.3 there is an XSS vulnerability in Vega expressions. Through a specially crafted Vega expression, an attacker could execute arbitrary javascript on a victim's machine. This is fixed in version 5.17.3","published":"2020-12-30T23:15:15.233Z","modified":"2026-07-09T00:37:10.408789Z","cvss":{"score":8.7,"severity":"HIGH","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N"},"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"npm","name":"vega","fixedVersion":"5.17.3"}],"fix":{"url":"https://github.com/vega/vega/pull/3019","label":"vega/vega#3019"},"references":[{"type":"ADVISORY","url":"https://github.com/vega/vega/issues/3018"},{"type":"ADVISORY","url":"https://github.com/vega/vega/pull/3019"},{"type":"ADVISORY","url":"https://github.com/vega/vega/releases/tag/v5.17.3"},{"type":"ADVISORY","url":"https://github.com/vega/vega/security/advisories/GHSA-r2qc-w64x-6j54"},{"type":"ADVISORY","url":"https://www.npmjs.com/package/vega"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-07-09T00:37:10.408789Z"}}