Vega Functions Project maintains a specialized data-visualization and analytics library that, despite a narrow product scope, occupies a notable position in analytics and business-intelligence tooling. Observed vulnerabilities in this vendor cluster around the core Vega Functions product itself; current severity, exploitation, and exposure metrics are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Vega Functions Project over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-26487MEDIUM Vega is a visualization grammar, a declarative format for creating, saving, and sharing interactive visualization designs.`lassoAppend' function accepts 3 arguments and internally | Mar 4, 2023 | 6.1 | 21 | NO | NO |
CVE-2023-26486MEDIUM Vega is a visualization grammar, a declarative format for creating, saving, and sharing interactive visualization designs. The Vega `scale` expression function has the ability to c | Mar 4, 2023 | 6.1 | 21 | NO | NO |
CVE-2025-66648MEDIUM vega-functions provides function implementations for the Vega expression language. Prior to version 6.1.1, for sites that allow users to supply untrusted user input, malicious use | Jan 5, 2026 | 6.1 | 19 | NO | NO |
CVE-2025-26619MEDIUM Vega is a visualization grammar, a declarative format for creating, saving, and sharing interactive visualization designs. In `vega` 5.30.0 and lower and in `vega-functions` 5.15.0 | Mar 27, 2025 | 6.1 | 18 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Vega Functions Project.
Media articles that mention a CVE ID that affects a product developed by Vega Functions Project — matched by CVE ID, not by vendor name.