WingNews logo WingNews
top | new | best | ask | show | jobs
top | item 41903404

(no title)

niel | 1 year ago

JSONPath-Plus is a widely used [0] JavaScript package to query JSON objects with the JSONPath query language.

Recent versions allow trivial RCE. [1]

[0] 800+ direct dependants https://www.npmjs.com/package/jsonpath-plus?activeTab=depend... [1] https://github.com/JSONPath-Plus/JSONPath/issues/226

discuss

order

unknown|1 year ago

[deleted]

powered by hn/api // news.ycombinator.com