Web Hack List

Collected research

Vega CVE-2025-59840 - Unusual XSS Technique toString gadget chains

Vega's sandboxed expression language forbids arbitrary function calls, but an object whose toString is set to a library method has that method invoked on coercion. Because the method calls one of its own properties with another as the argument, attacker-set properties supply both the callee and its argument, giving DOM XSS.

Record

Researcher
Nick Copi
Published by
Critical Thinking - Bug Bounty Podcast
Date
Format
Advisory
Topic
XSS

In the archive

Tags

This page is the archive's own catalogue record. The research is the work of Nick Copi, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .