Collected research
Vega CVE-2025-59840 - Unusual XSS Technique toString gadget chains
Vega's sandboxed expression language forbids arbitrary function calls, but an object whose toString is set to a library method has that method invoked on coercion. Because the method calls one of its own properties with another as the argument, attacker-set properties supply both the callee and its argument, giving DOM XSS.
Record
- Researcher
- Nick Copi
- Published by
- Critical Thinking - Bug Bounty Podcast
- Date
- Format
- Advisory
- Topic
- XSS
In the archive
Tags
This page is the archive's own catalogue record. The research is the work of Nick Copi, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .