Intel

AIKIDO-2025-10829

json5 is vulnerable to Use of Unmaintained Third Party Components

Use of Unmaintained Third Party Components Pre-CVE
Found by Aikido Intel before public disclosure or CVE publication.
Published Nov 19, 2025

50

Medium Risk

This Affects:

rustjson5
0.0.0 - *
Are you affected? Scan for Free

TL;DR

The json5 package will no longer be maintained.

Who does this affect?

You are affected if you are using this package.

Background info

json5 is vulnerable to Use of Unmaintained Third Party Components in all versions.

How to fix this

Remove any json5 package from your application. Please take a look at serde_json5, jsonc-parser or json-five instead.