CVE-2025-26619: Vega Cross-Site Scripting (XSS) via event filter when not using CSP mode expressionInterpeter
(updated )
In vega
5.30.0 and lower, vega-functions
5.15.0 and lower , it was possible to call JavaScript functions from the Vega expression language that were not meant to be supported.
References
Code Behaviors & Features
Detect and mitigate CVE-2025-26619 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →