Vulnerabilities
CVE-2025-59840 - Vega Cross-Site Scripting (XSS) via expressions abusing toString calls in enviro...
CVE ID : CVE-2025-59840 Published : Nov. 13, 2025, 8:15 p.m. | 1 hour, 27 minutes ago Description : Vega is a visualization grammar, a declarative format for creating, saving, and sharing interactive visualization designs. In Vega prior to version 6.2.0, applications meeting 2 conditions are at risk of arbitrary JavaScript code execution, even if