CVE-2025-65110 is a DOM XSS vulnerability in the Vega visualization grammar, affecting applications that expose Vega or Vega.View instances globally and process user-defined Vega JSON. Successful exploitation, requiring user interaction with a malicious specification, allows arbitrary JavaScript execution, compromising confidentiality and integrity. With a CVSS score of 8.1 (High), the attack vector is network-based with low complexity, but requires user interaction. There is currently no evidence of active exploitation, public exploit code, or significant community discussion.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 5.6.3CPE matchmatch criteria | cpe:2.3:a:vega_project:vega:*:*:*:*:*:node.js:*:* | ||
>= 6.0.0, < 6.1.2CPE matchmatch criteria | cpe:2.3:a:vega_project:vega:*:*:*:*:*:node.js:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.8 Bluesky, 0.5 Mastodon, and 1.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.
Vega XSS via expression abusing vlSelectionTuples function array map calls in environments with satisfactory function gadgets in the global scope
Jan 5, 2026vega-selections: Vega: Arbitrary code execution through malicious visualization definitions
Jan 5, 2026