Cross-Site Scripting Vulnerability in Vega-Functions by Vega
CVE-2025-66648

7.2HIGH

Key Information:

Vendor

Vega

Status
Vendor
CVE Published:
5 January 2026

What is CVE-2025-66648?

The vega-functions library, which implements functions for the Vega expression language, contains a vulnerability that allows for the execution of unintentional JavaScript in sites that accept untrusted user input. This is due to a flaw in an internal function that is not part of the public API. If not addressed, this could allow attackers to exploit the vulnerability and execute malicious scripts. The issue affects all versions prior to 6.1.1, and users must upgrade to this version or later to eliminate the risk, as there are no workarounds available.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

Affected Version(s)

vega < 6.1.1

References

CVSS V3.1

Score:
7.2
Severity:
HIGH
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.