216.73.217.22

CVE-2025-14896

· Published 18/12/2025 17:15 · Modified 19/12/2025 18:00

Labels: CVE-2025-14896 2025-12-18CVE-2025-14896[email protected]

Essential information

Published
18/12/2025 17:15
Modified
19/12/2025 18:00
Author
Creator
CVSS
8.7 HIGH (v3) 8.7 HIGH (v4.0)
CISA KEV
No
CWE
CVSS vector

CVSS metrics

Description

due to insufficient sanitazation in Vega’s `convert()` function when `safeMode` is enabled and the spec variable is an array. An attacker can craft a malicious Vega diagram specification that will allow them to send requests to any URL, including local file system paths, leading to exposure of sensitive information.

NVD status

Status
Awaiting Analysis — CVE has been marked for Analysis. Normally once in this state the CVE will be analyzed by NVD staff within 24 hours.
Source
[email protected]
NVD
View on NVD

References