Releases57
Frequency1 month 2 weeks
Last Release
Stars4.17K
Creates diagrams from textual descriptions!

CVE History

CVEPublishedCVSS v3CVSS v2
7.5 HIGH

due to insufficient sanitazation in Vega’s `convert()` function when `safeMode` is enabled and the spec variable is an array. An attacker can craft a malicious Vega diagram specification that will allow them to send requests to any URL, including local file system paths, leading to exposure of sensitive information.