{"id":"GHSA-cp47-r258-q626","aliases":[],"url":"https://o3.security/vulnerability/GHSA-cp47-r258-q626","summary":" Vega vulnerable to arbitrary code execution when clicking href links","details":" Vega is vulnerable to arbitrary code execution when clicking href links. Versions 5.4.1 and 4.5.1 contain a patch.","published":"2023-03-02T23:36:22Z","modified":"2023-03-02T23:36:22Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"npm","name":"vega","fixedVersion":"5.4.1"},{"ecosystem":"npm","name":"vega","fixedVersion":"4.5.1"}],"fix":{"url":"https://github.com/vega/vega/pull/1892","label":"vega/vega#1892"},"references":[{"type":"WEB","url":"https://github.com/vega/vega/security/advisories/GHSA-cp47-r258-q626"},{"type":"WEB","url":"https://github.com/vega/vega/pull/1892"},{"type":"WEB","url":"https://github.com/vega/vega/commit/692327013eb4dd5adec0c47a620181af1b135e2a"},{"type":"PACKAGE","url":"https://github.com/vega/vega"},{"type":"WEB","url":"https://github.com/vega/vega/commits/v4.5.1"},{"type":"WEB","url":"https://github.com/vega/vega/commits/v5.4.1"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2023-03-02T23:36:22Z"}}