dherault / dherault/serverless-offline

jsonpath-plus < 10.3.0 is vulnerable to Remote Code Execution

Open
#1,853 2 comments 7 reactions 0 assignees View on GitHub
Dominant language
JavaScript
Stars
5.3k
Forks
811
Avg merge
2d 4h
Merged PRs (30d)
3

Description

There is a vulnerability in the jsonpath-plus used in serverless-offline. This package are vulnerable to Remote Code Execution (RCE) due to improper input sanitization. An attacker can execute aribitrary code on the system by exploiting the unsafe default usage of eval='safe' mode. Could the package be updated to version 10.3.0 ?

Ref:
https://security.snyk.io/vuln/SNYK-JS-JSONPATHPLUS-8719585

Contributor guide

Open the contributing guide

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.