GHSA-5c5f-7vfq-3732CriticalCVSS 9.8

JMESPath for Ruby uses unsafe JSON.load when safe JSON.parse is preferable

Published
June 7, 2022
Last Modified
July 8, 2026

🔗 CVE IDs covered (1)

📋 Description

jmespath.rb (aka JMESPath for Ruby) before 1.6.1 uses JSON.load in a situation where JSON.parse is preferable.

🎯 Affected products1

  • rubygems/jmespath:< 1.6.1

🔗 References (11)