CVE-2025-14896

due to insufficient sanitazation in Vega’s `convert()` function when `safeMode` is enabled and the spec variable is an array. An attacker can craft a malicious Vega diagram specification that will allow them to send requests to any URL, including local file system paths, leading to exposure of sensitive information.
Configurations

No configuration.

History

No history.

Information

Published : 2025-12-18 17:15

Updated : 2025-12-19 18:00


NVD link : CVE-2025-14896

Mitre link : CVE-2025-14896

CVE.ORG link : CVE-2025-14896


JSON object : View

Products Affected

No product.

CWE
CWE-552

Files or Directories Accessible to External Parties