Skip to content

[GHSA-87r5-mp6g-5w5j] jsonpath has Arbitrary Code Injection via Unsafe Evaluation of JSON Path Expressions#6933

Merged
advisory-database[bot] merged 1 commit intoAlina-Podoba/advisory-improvement-6933from
Alina-Podoba-GHSA-87r5-mp6g-5w5j
Feb 17, 2026
Merged

[GHSA-87r5-mp6g-5w5j] jsonpath has Arbitrary Code Injection via Unsafe Evaluation of JSON Path Expressions#6933
advisory-database[bot] merged 1 commit intoAlina-Podoba/advisory-improvement-6933from
Alina-Podoba-GHSA-87r5-mp6g-5w5j

Conversation

@Alina-Podoba
Copy link

Updates

  • Affected products
  • CVSS v3
  • CVSS v4
  • Severity

Comments
Reviewing the source code of the newly released version 1.2.1 shows no substantial changes to the vulnerable evaluation logic in lib/handlers.js. It continues to rely on static-eval to process user-supplied JSON Path expressions, which is the root cause of the RCE vulnerability. Version 1.2.1 should NOT be listed as a patched version. There is currently no secure version of this package, and the advisory must be updated to prevent users from falling into a false sense of security by upgrading to an equally vulnerable version.

@github-actions github-actions bot changed the base branch from main to Alina-Podoba/advisory-improvement-6933 February 17, 2026 12:09
@advisory-database advisory-database bot merged commit b3dc8bc into Alina-Podoba/advisory-improvement-6933 Feb 17, 2026
4 checks passed
@advisory-database
Copy link
Contributor

Hi @Alina-Podoba! Thank you so much for contributing to the GitHub Advisory Database. This database is free, open, and accessible to all, and it's people like you who make it great. Thanks for choosing to help others. We hope you send in more contributions in the future!

@advisory-database advisory-database bot deleted the Alina-Podoba-GHSA-87r5-mp6g-5w5j branch February 17, 2026 21:47
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

Comments