TE
TechEcho
Home24h TopNewestBestAskShowJobs
GitHubTwitter
Home

TechEcho

A tech news platform built with Next.js, providing global tech news and discussions.

GitHubTwitter

Home

HomeNewestBestAskShowJobs

Resources

HackerNews APIOriginal HackerNewsNext.js

© 2025 TechEcho. All rights reserved.

JSONPath Plus Remote Code Execution (RCE) Vulnerability

2 pointsby niel7 months ago

1 comment

niel7 months ago
JSONPath-Plus is a widely used [0] JavaScript package to query JSON objects with the JSONPath query language.<p>Recent versions allow trivial RCE. [1]<p>[0] 800+ direct dependants <a href="https:&#x2F;&#x2F;www.npmjs.com&#x2F;package&#x2F;jsonpath-plus?activeTab=dependents" rel="nofollow">https:&#x2F;&#x2F;www.npmjs.com&#x2F;package&#x2F;jsonpath-plus?activeTab=depend...</a> [1] <a href="https:&#x2F;&#x2F;github.com&#x2F;JSONPath-Plus&#x2F;JSONPath&#x2F;issues&#x2F;226">https:&#x2F;&#x2F;github.com&#x2F;JSONPath-Plus&#x2F;JSONPath&#x2F;issues&#x2F;226</a>
评论 #41903435 未加载