This site is an independent open-source project and is not affiliated with, endorsed by, or sponsored by npm, Inc. or GitHub, Inc. The name “npm” is a registered trademark of npm, Inc., used here solely to describe compatibility and reference publicly available npm package data.
Version Details and Security Vulnerabilities
📦
json
9.0.3
Comparision Betweeen 9.0.3 and 9.0.2
Identify the differences between the current version of the package and the previous one.
Version
Dependencies
0
0
Dev Dependencies
6
0
Peer Dependencies
6
0
Distributed Files
N/A
N/A
Unpacked Size
N/A
N/A
Security Vulnerabilities
Security Details
Comprehensive list of direct or transitive vulnerabilities for version 9.0.3 of the package json.
All Security Vulnerabilities
All the vulnerabilities related to the version 9.0.3 of the package
Summary:
trentm/json vulnerable to command injection
Details:
This affects the package json before 10.0.0. It is possible to inject arbritary commands using the parseLookup function.