Cross-Site Scripting Vulnerability in Vega-Functions by Vega
CVE-2025-66648
What is CVE-2025-66648?
The vega-functions library, which implements functions for the Vega expression language, contains a vulnerability that allows for the execution of unintentional JavaScript in sites that accept untrusted user input. This is due to a flaw in an internal function that is not part of the public API. If not addressed, this could allow attackers to exploit the vulnerability and execute malicious scripts. The issue affects all versions prior to 6.1.1, and users must upgrade to this version or later to eliminate the risk, as there are no workarounds available.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
vega < 6.1.1
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved
