Skip to content

All versions of jsonpath have known vulnerability. #15

@crazyfraggle

Description

@crazyfraggle

The CVE states <1.2.0 but reports state that all versions are vulnerable https://nvd.nist.gov/vuln/detail/CVE-2026-1615

Developers are strongly advised to migrate to a secure alternative (such as jsonpath-plus or similar libraries that do not use eval/static-eval) or strictly validate all JSON Path inputs against a known allowlist.

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions