jsonpath-plus is vulnerable to Remote Code Execution (RCE)
90
Critical Risk
Affected versions of the package remain vulnerable to Remote Code Execution (RCE). CVE-2024-21534 was not fully addressed in version 10.0.0, leaving the possibility of RCE for certain inputs.
You are affected if you are using a version that falls within the vulnerable range.
jsonpath-plus is vulnerable to Remote Code Execution (RCE) in versions 0.1.0 - 10.1.0.
Upgrade the jsonpath-plus library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant