CVE-2025-14896
Unknown
Unknown - Not Provided
Server-Side Request Forgery in Vega `convert()` with safeMode
Publication date: 2025-12-18
Last updated on: 2025-12-18
Assigner: Snyk
Description
Description
due to insufficient sanitazation in Vegaβs `convert()` function when `safeMode` is enabled and the spec variable is an array. An attacker can craft a malicious Vega diagram specification that will allow them to send requests to any URL, including local file system paths, leading to exposure of sensitive information.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| vega | vega | * |
| yuzutech | kroki | * |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-552 | The product makes files or directories accessible to unauthorized actors, even though they should not be. |