{"id":"CVE-2025-25304","aliases":["GHSA-mp7w-mhcv-673j"],"url":"https://o3.security/vulnerability/CVE-2025-25304","summary":"Vega allows Cross-site Scripting via the vlSelectionTuples function","details":"Vega is a visualization grammar, a declarative format for creating, saving, and sharing interactive visualization designs. Prior to version 5.26.0 of vega and 5.4.2 of vega-selections, the `vlSelectionTuples` function can be used to call JavaScript functions, leading to cross-site scripting.`vlSelectionTuples` calls multiple functions that can be controlled by an attacker, including one call with an attacker-controlled argument. This can be used to call `Function()` with arbitrary JavaScript and the resulting function can be called with `vlSelectionTuples` or using a type coercion to call `toString` or `valueOf`. Version 5.26.0 of vega and 5.4.2 of vega-selections fix this issue.","published":"2025-02-14T19:28:00.388Z","modified":"2026-07-15T01:48:57.357283884Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"npm","name":"vega","fixedVersion":"5.26.0"},{"ecosystem":"npm","name":"vega-selections","fixedVersion":"5.4.2"}],"fix":{"url":"https://github.com/vega/vega/commit/9fb9ea07e27984394e463d286eb73944fa61411e","label":"vega/vega@9fb9ea0"},"references":[{"type":"WEB","url":"https://github.com/vega/vega/blob/b45cf431cd6c0d0c0e1567f087f9b3b55bc236fa/packages/vega-selections/src/selectionTuples.js#L14"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/25xxx/CVE-2025-25304.json"},{"type":"ADVISORY","url":"https://github.com/vega/vega/security/advisories/GHSA-mp7w-mhcv-673j"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-25304"},{"type":"FIX","url":"https://github.com/vega/vega/commit/9fb9ea07e27984394e463d286eb73944fa61411e"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-07-15T01:48:57.357283884Z"}}