CVE-2025-14896

Publication date

2025-12-18 16:20:15

Family

snyk

State

PUBLISHED

Description

due to insufficient sanitazation in Vega’s `convert()` function when `safeMode` is enabled and the spec variable is an array. An attacker can craft a malicious Vega diagram specification that will allow them to send requests to any URL, including local file system paths, leading to exposure of sensitive information.