{"id":"GHSA-cp47-r258-q626","summary":" Vega vulnerable to arbitrary code execution when clicking href links","details":" Vega is vulnerable to arbitrary code execution when clicking href links. Versions 5.4.1 and 4.5.1 contain a patch.","modified":"2023-03-02T23:36:22Z","published":"2023-03-02T23:36:22Z","database_specific":{"github_reviewed_at":"2023-03-02T23:36:22Z","nvd_published_at":null,"cwe_ids":[],"severity":"MODERATE","github_reviewed":true},"references":[{"type":"WEB","url":"https://github.com/vega/vega/security/advisories/GHSA-cp47-r258-q626"},{"type":"WEB","url":"https://github.com/vega/vega/pull/1892"},{"type":"WEB","url":"https://github.com/vega/vega/commit/692327013eb4dd5adec0c47a620181af1b135e2a"},{"type":"PACKAGE","url":"https://github.com/vega/vega"},{"type":"WEB","url":"https://github.com/vega/vega/commits/v4.5.1"},{"type":"WEB","url":"https://github.com/vega/vega/commits/v5.4.1"}],"affected":[{"package":{"name":"vega","ecosystem":"npm","purl":"pkg:npm/vega"},"ranges":[{"type":"SEMVER","events":[{"introduced":"5.0.0"},{"fixed":"5.4.1"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2023/03/GHSA-cp47-r258-q626/GHSA-cp47-r258-q626.json"}},{"package":{"name":"vega","ecosystem":"npm","purl":"pkg:npm/vega"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"4.5.1"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2023/03/GHSA-cp47-r258-q626/GHSA-cp47-r258-q626.json"}}],"schema_version":"1.9.0"}