CVE-2025-14896: Yuzutech Kroki
High severity, CVSS 7.5. EPSS: 0.3% chance of exploitation in the next 30 days.
due to insufficient sanitazation in Vega’s `convert()` function when `safeMode` is enabled and the spec variable is an array. An attacker can craft a malicious Vega diagram specification that will allow them to send requests to any URL, including local file system paths, leading to exposure of sensitive information.
Affected products
- Yuzutech Kroki: any version
Published 2025-12-18. Last modified 2026-06-17.