HIGH
GHSA-rrqv-vjrw-hrcr
Arbitrary Code Execution in json-ptr
Quick fix
GHSA-rrqv-vjrw-hrcr — json-ptr: upgrade to the fixed version with the command below.
npm install json-ptr@2.1.0Details
There is a security vulnerability in `json-ptr` versions prior to v2.1.0 in which an unscrupulous actor may execute arbitrary code. If your code sends un-sanitized user input to json-ptr's .get() method, your project is vulnerable to this injection-style vulnerability.
Are you affected?
Enter the version of the package you're using.
Affected packages
References
- https://github.com/418sec/json-ptr/pull/3[WEB]
- https://github.com/flitbit/json-ptr/blob/456a1728b45c8663bb1ac20a249c5fb17495ec6b/README.md#security-vulnerability-prior-to-v210[WEB]
- https://github.com/flitbit/json-ptr/blob/master/src/util.ts%23L174[WEB]
- https://snyk.io/vuln/SNYK-JAVA-ORGWEBJARSNPM-1038396[WEB]
- https://snyk.io/vuln/SNYK-JS-JSONPTR-1016939[WEB]
- https://www.huntr.dev/bounties/2-npm-json-ptr[WEB]
- https://www.npmjs.com/advisories/1706[WEB]
- https://www.npmjs.com/package/json-ptr[WEB]