Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Stored XSS in vega-lite #1635

Closed
nename0 opened this issue Dec 21, 2020 · 1 comment · Fixed by #1637
Closed

Stored XSS in vega-lite #1635

nename0 opened this issue Dec 21, 2020 · 1 comment · Fixed by #1637
Labels
security upstream This issue belongs to a library or component outside
Milestone

Comments

@nename0
Copy link

nename0 commented Dec 21, 2020

See: vega/vega#3018

Working demo on hackmd.io

@nename0
Copy link
Author

nename0 commented Dec 21, 2020

Maybe you could use vega-interpreter as mentioned here

Would this allow removing unsafe-eval from CSP?

@Yukaii Yukaii added security upstream This issue belongs to a library or component outside labels Dec 22, 2020
@Yukaii Yukaii added this to the Next milestone Dec 22, 2020
@Yukaii Yukaii modified the milestones: Next, 2.3.0 Dec 25, 2020
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
security upstream This issue belongs to a library or component outside
Projects
None yet
Development

Successfully merging a pull request may close this issue.

2 participants