Description
JSON Editor is a web-based tool to view, edit, format, and validate JSON. It has various modes such as a tree editor, a code editor, and a plain text editor. The jsoneditor package is vulnerable to ReDoS (regular expression denial of service).
Recommendation
Update the jsoneditor
package to the latest compatible version. Followings are version details:
- Affected version(s): < 9.5.6
- Patched version(s): 9.5.6
References
Related Issues
- Command Injection in lodash (GHSA-35jh-r3h4-6jhm) - CVE-2021-23337
- Bootstrap Cross-Site Scripting (XSS) vulnerability - CVE-2024-6531
- @intlify/shared Prototype Pollution vulnerability - CVE-2024-52810
- DOMPurify allows tampering by prototype pollution - CVE-2024-45801
- Tags:
- npm
- jsoneditor
Anything's wrong? Let us know Last updated on February 12, 2025