VDB
Sign up
CRITICAL9.8

GHSA-vh6r-g38f-q3w8

Validation bypass in jpv

Quick fix

GHSA-vh6r-g38f-q3w8 — jpv: upgrade to the fixed version with the command below.

npm install jpv@2.2.2

Details

jpv (aka Json Pattern Validator) before 2.2.2 does not properly validate input, as demonstrated by a corrupted array.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/jpv
Introduced in: 0Fixed in: 2.2.2
Fixnpm install jpv@2.2.2

References