OsVault/npm/json
npm5 critical

json

168 known vulnerabilities · 5 critical · 13 high

CVE-2020-7712HIGH

trentm/json vulnerable to command injection

Published May 6, 2021
MAL-2025-191473

Malicious code in chai-jsons (npm)

Published Nov 26, 2025
MAL-2025-191482

Malicious code in wartsila-application-json (npm)

Published Nov 27, 2025
CVE-2026-1615

jsonpath has Arbitrary Code Injection via Unsafe Evaluation of JSON Path Expressions

Published Feb 9, 2026
GHSA-8g29-8xwr-qmhr

@grackle-ai/server JSON.parse lacks try-catch logic in its gRPC Service AdapterConfig Handling

Published Mar 25, 2026
MAL-2026-895

Malicious code in json-mapping-src (npm)

Published Feb 13, 2026
CVE-2015-9235CRITICAL

Verification Bypass in jsonwebtoken

Published Oct 9, 2018
CVE-2026-22028

Preact has JSON VNode Injection issue

Published Jan 7, 2026
CVE-2025-57320

json-schema-editor-visual vulnerable to prototype pollution

Published Sep 24, 2025
MAL-2026-1368

Malicious code in json-specparse (npm)

Published Mar 12, 2026
CVE-2017-1000042MEDIUM

Content Injection via TileJSON attribute in mapbox.js

Published Nov 9, 2018
CVE-2026-32763

SQL Injection via unsanitized JSON path keys when ignoring/silencing compilation errors or using `Kysely<any>`.

Published Mar 18, 2026
CVE-2018-1107MEDIUM

Regular expression deinal of service (ReDoS) in is-my-json-valid

Published Jan 6, 2022
CVE-2021-23509MEDIUM

Prototype Pollution in json-ptr

Published Nov 8, 2021
CVE-2022-46175HIGH

Prototype Pollution in JSON5 via Parse Method

Published Dec 29, 2022
CVE-2026-23736

seroval Affected by Prototype Pollution via JSON Deserialization

Published Jan 21, 2026
CVE-2016-1000225

SQL Injection via GeoJSON in sequelize

Published Sep 1, 2020
CVE-2018-3711HIGH

Denial of Service vulnerability with large JSON payloads in fastify

Published Jul 18, 2018
CVE-2025-1302

JSONPath Plus allows Remote Code Execution

Published Feb 15, 2025
CVE-2020-8268HIGH

Prototype pollution in json8-merge-patch

Published May 10, 2021
MAL-2025-192711

Malicious code in assert-json-not (npm)

Published Dec 23, 2025
MAL-2025-192811

Malicious code in jsonauto (npm)

Published Dec 23, 2025
CVE-2020-7770MEDIUM

Prototype pollution in json8

Published May 10, 2021
MAL-2025-192964

Malicious code in @peter_wilson12091/internal-json-test-parser (npm)

Published Dec 30, 2025
CVE-2026-23737

seroval Affected by Remote Code Execution via JSON Deserialization

Published Jan 21, 2026
CVE-2020-8237HIGH

Uncontrolled Resource Consumption in json-bigint

Published May 7, 2021
CVE-2021-4329MEDIUM

json-logic-js Command Injection vulnerability

Published Mar 5, 2023
CVE-2021-23820MEDIUM

Prototype Pollution in json-pointer

Published Nov 8, 2021
CVE-2025-61140

JSONPath vulnerable to Prototype Pollution due to insufficient input validation of object keys in lib/index.js

Published Jan 28, 2026
MAL-2022-3478

Malicious code in grunt-modify-json (npm)

Published Jun 20, 2022
MAL-2022-1896

Malicious code in checkpackagejson (npm)

Published Jun 20, 2022
CVE-2018-25053MEDIUM

Json2html vulnerable to cross-site scripting

Published Dec 28, 2022
CVE-2026-33331

oRPC has Stored XSS in OpenAPI Reference Plugin via unescaped JSON.stringify

Published Mar 20, 2026
MAL-2022-4174

Malicious code in kiota-serialization-json (npm)

Published Jun 20, 2022
CVE-2021-27884MEDIUM

Weak JSON Web Token in yapi-vendor

Published Mar 26, 2021
MAL-2022-6327

Malicious code in strip-json-combmentd (npm)

Published Aug 19, 2022
CVE-2014-4671MEDIUM

Rosetta-Flash JSONP Vulnerability in hapi

Published Aug 31, 2020
MAL-2022-2

Malicious code in --hiljson (npm)

Published Dec 7, 2022
MAL-2024-11047

Malicious code in json-schema-editor-visual-yapi (npm)

Published Nov 27, 2024
MAL-2022-2444

Malicious code in deps-json-webpack-plugin (npm)

Published Jun 20, 2022
GHSA-f7fh-qg34-x2xh

OpenClaw: CDP /json/version WebSocket URL could pivot to untrusted second-hop targets

Published Apr 17, 2026
CVE-2022-23631CRITICAL

Prototype Pollution leading to Remote Code Execution in superjson

Published Feb 9, 2022
CVE-2026-30951

Sequelize v6 Vulnerable to SQL Injection via JSON Column Cast Type

Published Mar 11, 2026
MAL-2024-7705

Malicious code in flammerxdjson (npm)

Published Jul 11, 2024
CVE-2016-10610HIGH

Downloads Resources over HTTP in unicode-json

Published Feb 18, 2019
MAL-2022-736

Malicious code in @wso-utils/json-mapper (npm)

Published Jun 20, 2022
CVE-2024-27307CRITICAL

JSONata expression can pollute the "Object" prototype

Published Mar 4, 2024
CVE-2018-1000096HIGH

tiny-json-http missing SSL certificate validation

Published Mar 13, 2018
MAL-2024-11136

Malicious code in discord-json-requests (npm)

Published Nov 29, 2024
MAL-2023-1046

Malicious code in json2stringfy (npm)

Published May 12, 2023
CVE-2026-25725

Claude Code has Sandbox Escape via Persistent Configuration Injection in settings.json

Published Feb 6, 2026
CVE-2022-42743MEDIUM

deep-parse-json vulnerable to Prototype Pollution

Published Nov 4, 2022
MAL-2025-47031

Malicious code in @jsonjoy-com/base64 (npm)

Published Sep 11, 2025
MAL-2025-47073

Malicious code in jsonjoy.com (npm)

Published Sep 11, 2025
MAL-2025-191202

Malicious code in @clausehq/flows-step-jsontoxml (npm)

Published Nov 25, 2025
MAL-2025-6170

Malicious code in json-cookie-csv (npm)

Published Jul 22, 2025
MAL-2026-1017

Malicious code in json-mapping-srcs (npm)

Published Feb 24, 2026
CVE-2025-57350

CSVTOJSON has a prototype pollution vulnerability

Published Sep 24, 2025
MAL-2025-192808

Malicious code in jsonapptoken (npm)

Published Dec 23, 2025
MAL-2025-192813

Malicious code in jsonupon (npm)

Published Dec 23, 2025
CVE-2026-33442

Kysely has a MySQL SQL Injection via Backslash Escape Bypass in non-type-safe usage of JSON path keys.

Published Mar 20, 2026
MAL-2025-3527

Malicious code in jsonspecific (npm)

Published Apr 29, 2025
MAL-2025-47319

Malicious code in jsonwebjstoken (npm)

Published Sep 16, 2025
MAL-2026-392

Malicious code in jsonwebauth (npm)

Published Jan 21, 2026
CVE-2021-3822HIGH

Regular Expression Denial of Service in jsoneditor

Published Sep 29, 2021
CVE-2017-16113HIGH

Regular Expression Denial of Service in parsejson

Published Jul 24, 2018
CVE-2020-23849MEDIUM

Cross-site Scripting in jsoneditor

Published Oct 12, 2021
CVE-2022-36010CRITICAL

React Editable Json Tree vulnerable to arbitrary code execution via function parsing

Published Aug 18, 2022
MAL-2026-2676

Malicious code in moscova-plural-json-parser (npm)

Published Apr 15, 2026
CVE-2017-1000043MEDIUM

Content Injection via TileJSON Name in mapbox.js

Published Nov 9, 2018
MAL-2025-588

Malicious code in @adsk-forks/jsonpath (npm)

Published Jan 27, 2025
MAL-2025-191362

Malicious code in @voiceflow/npm-package-json-lint-config (npm)

Published Nov 25, 2025
MAL-2024-11133

Malicious code in crypto-jsonwebtoken (npm)

Published Nov 29, 2024
MAL-2025-190774

Malicious code in korea-administrative-area-geo-json-util (npm)

Published Nov 24, 2025
CVE-2025-57318

csvjson vulnerable to prototype injection

Published Sep 24, 2025
MAL-2025-191426

Malicious code in simplejsonform (npm)

Published Nov 24, 2025
CVE-2020-7766HIGH

Arbitrary Code Execution in json-ptr

Published May 10, 2021
CVE-2022-30241MEDIUM

Cross-site Scripting in jquery.json-viewer

Published May 5, 2022
MAL-2025-192812

Malicious code in jsonrecap (npm)

Published Dec 23, 2025
MAL-2025-3578

Malicious code in discord-json-parser (npm)

Published May 2, 2025
MAL-2022-1585

Malicious code in bitcoin-json-rpc-adapter (npm)

Published Jun 20, 2022
CVE-2024-29651HIGH

json-schema-ref-parser Prototype Pollution issue

Published May 20, 2024
MAL-2026-1569

Malicious code in transform-json-strings (npm)

Published Mar 16, 2026
GHSA-hpwf-8g29-85qm

Nest Affected by DoS via Recursive handleData in JsonSocket (TCP Transport)

Published Apr 14, 2026
MAL-2024-11764

Malicious code in plugin-proposal-json-strings (npm)

Published Dec 11, 2024
CVE-2024-21534CRITICAL

JSONPath Plus Remote Code Execution (RCE) Vulnerability

Published Oct 11, 2024
CVE-2020-7709MEDIUM

Prototype pollution in json-pointer

Published May 10, 2021
MAL-2022-6519

Malicious code in testherejson (npm)

Published Dec 7, 2022
CVE-2026-28794

`@orpc/client` has Prototype Pollution via `StandardRPCJsonSerializer` Deserialization

Published Mar 2, 2026
MAL-2025-192384

Malicious code in jsonify-errors (npm)

Published Dec 9, 2025
CVE-2022-41714MEDIUM

fastest-json-copy vulnerable to Prototype Pollution

Published Nov 4, 2022
MAL-2025-4839

Malicious code in jsons-pack (npm)

Published Jun 10, 2025
MAL-2026-725

Malicious code in json-mapping-source (npm)

Published Feb 4, 2026
MAL-2025-3525

Malicious code in jsonpacks (npm)

Published Apr 29, 2025
MAL-2025-3526

Malicious code in jsonsecs (npm)

Published Apr 29, 2025
CVE-2024-6376

ejson shell parser in MongoDB Compass maybe bypassed

Published Jul 1, 2024
MAL-2025-192321

Malicious code in json-map-source (npm)

Published Dec 5, 2025
MAL-2025-5502

Malicious code in jsonlogs (npm)

Published Jun 30, 2025
MAL-2025-2270

Malicious code in prop2json (npm)

Published Mar 11, 2025
GHSA-ccgf-5rwj-j3hv

TeleJSON: DOM XSS via unsanitised constructor name in `new Function()`

Published Apr 2, 2026
MAL-2026-160

Malicious code in json-mappings (npm)

Published Jan 8, 2026
CVE-2020-28429HIGH

Command Injection in geojson2kml

Published May 10, 2021
MAL-2026-1977

Malicious code in json-bundling (npm)

Published Mar 20, 2026
CVE-2026-25544

@payloadcms/drizzle has SQL Injection in JSON/RichText Queries on PostgreSQL/SQLite Adapters

Published Feb 5, 2026
MAL-2025-191114

Malicious code in jsonsurge (npm)

Published Nov 24, 2025
MAL-2026-3008

Malicious code in json-spacer (npm)

Published Apr 23, 2026
MAL-2022-157

Malicious code in @bugbounty-automation/deps-json-webpack-plugin (npm)

Published Jun 20, 2022
MAL-2026-1978

Malicious code in json-specular (npm)

Published Mar 20, 2026
MAL-2026-3007

Malicious code in json-dec (npm)

Published Apr 23, 2026
MAL-2022-2588

Malicious code in dr-json (npm)

Published Jun 20, 2022
MAL-2025-192584

Malicious code in jsondatatoruby (npm)

Published Dec 16, 2025
MAL-2025-5503

Malicious code in jsontostr (npm)

Published Jun 30, 2025
MAL-2024-11803

Malicious code in discord-json-scaller (npm)

Published Dec 12, 2024
MAL-2022-3633

Malicious code in hiljsonhil (npm)

Published Dec 7, 2022
MAL-2025-2262

Malicious code in json-schema-verify (npm)

Published Mar 11, 2025
MAL-2022-4845

Malicious code in ng-json-explorer (npm)

Published Jun 20, 2022
MAL-2023-753

Malicious code in sa-docs-to-json (npm)

Published Jan 11, 2023
MAL-2026-1757

Malicious code in jsondatahandle (npm)

Published Mar 18, 2026
MAL-2025-3271

Malicious code in node-json-converter (npm)

Published Apr 19, 2025
MAL-2026-2200

Malicious code in json-lucide (npm)

Published Mar 25, 2026
MAL-2026-360

Malicious code in excel-to-json-test (npm)

Published Jan 20, 2026
MAL-2022-5181

Malicious code in package-lock.json-dependency (npm)

Published Jun 20, 2022
MAL-2025-5195

Malicious code in jsonwepjoken (npm)

Published Jun 20, 2025
MAL-2023-1045

Malicious code in json2double (npm)

Published May 12, 2023
MAL-2026-1213

Malicious code in turbo-json-parser (npm)

Published Mar 3, 2026
MAL-2026-3301

Malicious code in ally-json-threat-protect (npm)

Published May 3, 2026
MAL-2025-191056

Malicious code in @tiaanduplessis/json (npm)

Published Nov 24, 2025
MAL-2024-10761

Malicious code in module-json-validator (npm)

Published Nov 14, 2024
MAL-2022-5590

Malicious code in rapidjson (npm)

Published Jun 20, 2022
GHSA-53p3-c7vp-4mcc

Trix is vulnerable to XSS through JSON deserialization bypass in drag-and-drop (Level0InputController)

Published Mar 29, 2026
MAL-2026-2368

Malicious code in json-mapping-token (npm)

Published Mar 24, 2026
MAL-2025-191190

Malicious code in @antstackio/json-to-graphql (npm)

Published Nov 25, 2025
MAL-2023-8275

Malicious code in jsonpjs (npm)

Published Oct 2, 2023
MAL-2024-10983

Malicious code in json-tree-preview (npm)

Published Nov 27, 2024
CVE-2022-25921HIGH

morgan-json vulnerable to Arbitrary Code Execution

Published Aug 29, 2022
MAL-2025-192307

Malicious code in jsonify-settings (npm)

Published Dec 5, 2025
MAL-2022-4257

Malicious code in language-jsonnet (npm)

Published Jun 20, 2022
MAL-2022-6114

Malicious code in shubholic-test.json (npm)

Published Jun 20, 2022
CVE-2021-23807MEDIUM

Prototype Pollution in node-jsonpointer

Published Nov 8, 2021
MAL-2022-7199

Malicious code in wm-package-json-validate (npm)

Published Jun 20, 2022
CVE-2025-9910

jsondiffpatch is vulnerable to Cross-site Scripting (XSS) via HtmlFormatter::nodeBegin

Published Sep 11, 2025
MAL-2026-2237

Malicious code in jsonify-builder (npm)

Published Mar 26, 2026
CVE-2019-19507MEDIUM

Validation bypass is possible in Json Pattern Validator

Published Dec 4, 2019
MAL-2022-4072

Malicious code in json-rpc-adapter (npm)

Published Jun 20, 2022
MAL-2022-4073

Malicious code in json-st7rzingif-safe (npm)

Published Aug 19, 2022
MAL-2022-5252

Malicious code in paytm-kapacitor-simplejson-datasource (npm)

Published Jun 20, 2022
MAL-2022-4074

Malicious code in jsonstsream (npm)

Published Aug 19, 2022
MAL-2026-2367

Malicious code in json-mapping-fetch (npm)

Published Mar 24, 2026
MAL-2026-552

Malicious code in json-mapping-web (npm)

Published Jan 28, 2026
MAL-2025-192807

Malicious code in json-panels (npm)

Published Dec 23, 2025
MAL-2025-3193

Malicious code in mongoose-to-json (npm)

Published Apr 9, 2025
MAL-2026-1297

Malicious code in json-merge-tool (npm)

Published Mar 9, 2026
MAL-2026-1298

Malicious code in jsonify-core (npm)

Published Mar 9, 2026
MAL-2026-1925

Malicious code in jsonify-parser (npm)

Published Mar 19, 2026
MAL-2026-1962

Malicious code in parsejson-pro (npm)

Published Mar 20, 2026
MAL-2026-1968

Malicious code in safe-json-parsex (npm)

Published Mar 20, 2026
MAL-2025-192809

Malicious code in jsonauth (npm)

Published Dec 23, 2025
MAL-2025-192810

Malicious code in jsonauthcap (npm)

Published Dec 23, 2025
MAL-2025-711

Malicious code in nlohmann-json (npm)

Published Jan 31, 2025
MAL-2026-161

Malicious code in jsonify-setting (npm)

Published Jan 8, 2026
MAL-2026-1470

Malicious code in n8n-nodes-json-helper (npm)

Published Mar 16, 2026
MAL-2025-47566

Malicious code in postman-json (npm)

Published Sep 25, 2025
MAL-2026-819

Malicious code in json-mapping-sources (npm)

Published Feb 9, 2026
MAL-2026-820

Malicious code in json-web-sources (npm)

Published Feb 9, 2026
MAL-2025-5281

Malicious code in json-webhooks (npm)

Published Jun 26, 2025
MAL-2025-5282

Malicious code in jsonspack-logger (npm)

Published Jun 26, 2025
MAL-2026-1935

Malicious code in jsonify-bundler (npm)

Published Mar 20, 2026
MAL-2026-1952

Malicious code in json-parse-genie (npm)

Published Mar 20, 2026
Check your entire dependency tree at onceRun dependency scan →