due to insufficient sanitazation in Vega’s `convert()` function when `safeMode` is enabled and the spec variable is an array. An attacker can craft a malicious Vega diagram specification that will allow them to send requests to any URL, including local file system paths, leading to exposure of sensitive information.
Metrics
Affected Vendors & Products
References
History
Thu, 18 Dec 2025 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 18 Dec 2025 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | due to insufficient sanitazation in Vega’s `convert()` function when `safeMode` is enabled and the spec variable is an array. An attacker can craft a malicious Vega diagram specification that will allow them to send requests to any URL, including local file system paths, leading to exposure of sensitive information. | |
| Weaknesses | CWE-552 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: snyk
Published:
Updated: 2025-12-18T16:49:46.024Z
Reserved: 2025-12-18T16:19:38.828Z
Link: CVE-2025-14896
Updated: 2025-12-18T16:49:42.159Z
Status : Received
Published: 2025-12-18T17:15:47.690
Modified: 2025-12-18T17:15:47.690
Link: CVE-2025-14896
No data.
OpenCVE Enrichment
No data.