pkg:npm/vega-expression

1 total CVEHIGH1

✅ Check your installed version

All known vulnerabilities

  • HIGH8.1CVE-2025-59840Vega Cross-Site Scripting (XSS) via expressions abusing toString calls in environments using the VEGA_DEBUG global variable
    >= 6.0.0, < 6.1.0