CVE-2025-65110 - Vega Cross-Site Scripting (XSS) via expression abusing vlSelectionTuples functio

CVE-2025-65110 - Vega Cross-Site Scripting (XSS) via expression abusing vlSelectionTuples functio

CVE ID : CVE-2025-65110 Published : Jan. 5, 2026, 10:15 p.m. | 57 minutes ago Description : Vega is a visualization grammar, a declarative format for creating, saving, and sharing interactive visualization designs. Prior to versions 6.1.2 and 5.6.3, applications meeting two conditions are at risk of arbitrary JavaScript code execution, even if

CVE Details

Published
Jan. 5, 2026
Impact: code execution

Source: Telegram CVE Monitor