Skip to content

Vega Cross-Site Scripting (XSS) via expressions abusing toString calls in environments using the VEGA_DEBUG global variable

High severity GitHub Reviewed Published Nov 13, 2025 in vega/vega • Updated Nov 14, 2025

No open alerts for this advisory

Give feedback on Dependabot alerts