CVE-2025-14896

Severity CVSS v4.0:
HIGH
Type:
Unavailable / Other
Publication date:
18/12/2025
Last modified:
19/12/2025

Description

due to insufficient sanitazation in Vega’s `convert()` function when `safeMode` is enabled and the spec variable is an array. An attacker can craft a malicious Vega diagram specification that will allow them to send requests to any URL, including local file system paths, leading to exposure of sensitive information.