JSONPath Plus allows Remote Code Execution
High severity
GitHub Reviewed
Published
Feb 15, 2025
to the GitHub Advisory Database
•
Updated Feb 18, 2025
Description
Published by the National Vulnerability Database
Feb 15, 2025
Published to the GitHub Advisory Database
Feb 15, 2025
Reviewed
Feb 18, 2025
Last updated
Feb 18, 2025
Versions of the package jsonpath-plus before 10.3.0 are vulnerable to Remote Code Execution (RCE) due to improper input sanitization. An attacker can execute aribitrary code on the system by exploiting the unsafe default usage of eval='safe' mode.
Note:
This is caused by an incomplete fix for CVE-2024-21534.
References