{"id":1908984,"name":"json-ptr","ecosystem":"npm","description":"A complete implementation of JSON Pointer (RFC 6901) for nodejs and modern browsers.","homepage":"https://github.com/flitbit/json-ptr#readme","licenses":"MIT","normalized_licenses":["MIT"],"repository_url":"https://github.com/flitbit/json-ptr","keywords_array":["6901","json","pointers","fragmentid"],"namespace":null,"versions_count":91,"first_release_published_at":"2013-06-11T16:01:46.024Z","latest_release_published_at":"2022-07-13T00:10:55.488Z","latest_release_number":"3.1.1","last_synced_at":"2026-06-29T11:35:25.313Z","created_at":"2022-04-09T18:12:27.046Z","updated_at":"2026-06-29T11:35:25.313Z","registry_url":"https://www.npmjs.com/package/json-ptr","install_command":"npm install json-ptr","documentation_url":null,"metadata":{"funding":null,"dist-tags":{"latest":"3.1.1","ts":"1.2.1-ts.cf62f17","master":"3.0.2-master.50697cc","dependabot-npm-and-yarn-lodash-4-17-19":"1.3.2-dependabot-npm-and-yarn-lodash-4-17-19.7fd4b3e","issue-28-and-30":"2.0.1-issue-28-and-30.f825bd7","issue-36":"2.1.1-issue-36.f2a3959","relative":"2.1.2-relative.f48c5e7","packaging-rollup":"2.2.1-packaging-rollup.7af30ca","older-nodes":"3.0.1-older-nodes.e0918b8","bug-issue-48":"3.0.2-bug-issue-48.6c9db9f","main":"3.1.2-main.1988f05","fix-examples":"3.1.1-fix-examples.80a275d","symbols":"3.1.1-symbols.0e6db58","dependabot-npm-and-yarn-minimist-1-2-6":"3.1.1-dependabot-npm-and-yarn-minimist-1-2-6.98d2cb6","dependabot-npm-and-yarn-json5-2-2-3":"3.1.2-dependabot-npm-and-yarn-json5-2-2-3.c209166","dependabot-npm-and-yarn-webpack-5-76-0":"3.1.2-dependabot-npm-and-yarn-webpack-5-76-0.29bfad0"}},"repo_metadata":{"id":37925942,"uuid":"10194071","full_name":"flitbit/json-ptr","owner":"flitbit","description":"A complete implementation of JSON Pointer (RFC 6901) for nodejs and modern browsers.","archived":false,"fork":false,"pushed_at":"2023-03-14T20:36:49.000Z","size":1625,"stargazers_count":88,"open_issues_count":5,"forks_count":28,"subscribers_count":4,"default_branch":"main","last_synced_at":"2024-05-22T05:42:24.193Z","etag":null,"topics":[],"latest_commit_sha":null,"homepage":"","language":"TypeScript","has_issues":true,"has_wiki":null,"has_pages":null,"mirror_url":null,"source_name":null,"license":"mit","status":null,"scm":"git","pull_requests_enabled":true,"icon_url":"https://github.com/flitbit.png","metadata":{"files":{"readme":"README.md","changelog":null,"contributing":null,"funding":null,"license":"LICENSE","code_of_conduct":null,"threat_model":null,"audit":null,"citation":null,"codeowners":null,"security":null,"support":null,"governance":null,"roadmap":null,"authors":null,"dei":null,"publiccode":null,"codemeta":null}},"created_at":"2013-05-21T11:26:18.000Z","updated_at":"2024-06-18T12:38:18.862Z","dependencies_parsed_at":"2024-06-18T12:38:10.034Z","dependency_job_id":"a12f9cb0-54c4-440f-adbb-5c029605bc5b","html_url":"https://github.com/flitbit/json-ptr","commit_stats":{"total_commits":181,"total_committers":15,"mean_commits":"12.066666666666666","dds":"0.15469613259668513","last_synced_commit":"1988f0582be565610f3f706e6aae865586d9314a"},"previous_names":[],"tags_count":23,"template":false,"template_full_name":null,"repository_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/flitbit%2Fjson-ptr","tags_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/flitbit%2Fjson-ptr/tags","releases_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/flitbit%2Fjson-ptr/releases","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/flitbit%2Fjson-ptr/manifests","owner_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners/flitbit","download_url":"https://codeload.github.com/flitbit/json-ptr/tar.gz/refs/heads/main","host":{"name":"GitHub","url":"https://github.com","kind":"github","repositories_count":217840935,"owners_count":16239158,"icon_url":"https://github.com/github.png","version":null,"created_at":"2022-05-30T11:31:42.601Z","updated_at":"2022-07-04T15:15:14.044Z","host_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub","repositories_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories","repository_names_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repository_names","owners_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners"},"owner_record":{"login":"flitbit","name":"flitbit","uuid":"1213114","kind":"organization","description":"","email":"code@flitbit.org","website":null,"location":null,"twitter":null,"company":null,"icon_url":"https://avatars.githubusercontent.com/u/1213114?v=4","repositories_count":76,"last_synced_at":"2024-04-12T23:28:32.941Z","metadata":{"has_sponsors_listing":false},"html_url":"https://github.com/flitbit","funding_links":[],"total_stars":3158,"followers":4,"following":0,"created_at":"2022-11-02T16:26:56.561Z","updated_at":"2024-04-12T23:28:56.516Z","owner_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners/flitbit","repositories_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners/flitbit/repositories"},"tags":[{"name":"v3.1.1","sha":"1988f0582be565610f3f706e6aae865586d9314a","kind":"tag","published_at":"2022-07-13T00:09:28.000Z","download_url":"https://codeload.github.com/flitbit/json-ptr/tar.gz/v3.1.1","html_url":"https://github.com/flitbit/json-ptr/releases/tag/v3.1.1","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/flitbit%2Fjson-ptr/tags/v3.1.1","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/flitbit%2Fjson-ptr/tags/v3.1.1/manifests"},{"name":"v3.1.0","sha":"02aa710da1b426d03ae045ba6be832a6685f2af5","kind":"tag","published_at":"2022-02-02T21:51:51.000Z","download_url":"https://codeload.github.com/flitbit/json-ptr/tar.gz/v3.1.0","html_url":"https://github.com/flitbit/json-ptr/releases/tag/v3.1.0","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/flitbit%2Fjson-ptr/tags/v3.1.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/flitbit%2Fjson-ptr/tags/v3.1.0/manifests"},{"name":"v3.0.1","sha":"a2e00556b2d39ef69a6fddf24cc3a4d8e07e4549","kind":"tag","published_at":"2021-11-19T23:31:57.000Z","download_url":"https://codeload.github.com/flitbit/json-ptr/tar.gz/v3.0.1","html_url":"https://github.com/flitbit/json-ptr/releases/tag/v3.0.1","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/flitbit%2Fjson-ptr/tags/v3.0.1","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/flitbit%2Fjson-ptr/tags/v3.0.1/manifests"},{"name":"v3.0.0","sha":"2d8c1ab7ddec15ce5f6e94867de9a2abf5c41cf6","kind":"tag","published_at":"2021-10-26T15:57:38.000Z","download_url":"https://codeload.github.com/flitbit/json-ptr/tar.gz/v3.0.0","html_url":"https://github.com/flitbit/json-ptr/releases/tag/v3.0.0","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/flitbit%2Fjson-ptr/tags/v3.0.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/flitbit%2Fjson-ptr/tags/v3.0.0/manifests"},{"name":"v2.2.0","sha":"4ed0dd19f9731de8ce3d7b983c341a22c7768b33","kind":"tag","published_at":"2021-05-14T12:41:51.000Z","download_url":"https://codeload.github.com/flitbit/json-ptr/tar.gz/v2.2.0","html_url":"https://github.com/flitbit/json-ptr/releases/tag/v2.2.0","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/flitbit%2Fjson-ptr/tags/v2.2.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/flitbit%2Fjson-ptr/tags/v2.2.0/manifests"},{"name":"v2.1.2","sha":"51308ff812c117aa05c8b86b6e343494ae7c2de3","kind":"tag","published_at":"2021-05-13T20:38:04.000Z","download_url":"https://codeload.github.com/flitbit/json-ptr/tar.gz/v2.1.2","html_url":"https://github.com/flitbit/json-ptr/releases/tag/v2.1.2","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/flitbit%2Fjson-ptr/tags/v2.1.2","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/flitbit%2Fjson-ptr/tags/v2.1.2/manifests"},{"name":"v2.1.1","sha":"bdd63172d8c391a68fbf19337d2f2efc31f15503","kind":"tag","published_at":"2021-05-12T20:20:41.000Z","download_url":"https://codeload.github.com/flitbit/json-ptr/tar.gz/v2.1.1","html_url":"https://github.com/flitbit/json-ptr/releases/tag/v2.1.1","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/flitbit%2Fjson-ptr/tags/v2.1.1","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/flitbit%2Fjson-ptr/tags/v2.1.1/manifests"},{"name":"v2.1.0","sha":"6efd1ec79319240de3a550aff164726405c7f98d","kind":"tag","published_at":"2021-05-12T18:39:23.000Z","download_url":"https://codeload.github.com/flitbit/json-ptr/tar.gz/v2.1.0","html_url":"https://github.com/flitbit/json-ptr/releases/tag/v2.1.0","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/flitbit%2Fjson-ptr/tags/v2.1.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/flitbit%2Fjson-ptr/tags/v2.1.0/manifests"},{"name":"v2.0.0","sha":"bd9903122e10f8ea822d6ff924e3bb5d07274714","kind":"tag","published_at":"2020-10-21T19:17:21.000Z","download_url":"https://codeload.github.com/flitbit/json-ptr/tar.gz/v2.0.0","html_url":"https://github.com/flitbit/json-ptr/releases/tag/v2.0.0","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/flitbit%2Fjson-ptr/tags/v2.0.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/flitbit%2Fjson-ptr/tags/v2.0.0/manifests"},{"name":"v1.3.2","sha":"10cfb6b4cf33991cd0650211131154cae97f94ff","kind":"tag","published_at":"2020-07-20T12:26:48.000Z","download_url":"https://codeload.github.com/flitbit/json-ptr/tar.gz/v1.3.2","html_url":"https://github.com/flitbit/json-ptr/releases/tag/v1.3.2","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/flitbit%2Fjson-ptr/tags/v1.3.2","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/flitbit%2Fjson-ptr/tags/v1.3.2/manifests"},{"name":"v1.3.1","sha":"3531b8f437a5bec4dbc6d359897af00895d4fa99","kind":"tag","published_at":"2020-07-12T15:55:33.000Z","download_url":"https://codeload.github.com/flitbit/json-ptr/tar.gz/v1.3.1","html_url":"https://github.com/flitbit/json-ptr/releases/tag/v1.3.1","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/flitbit%2Fjson-ptr/tags/v1.3.1","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/flitbit%2Fjson-ptr/tags/v1.3.1/manifests"},{"name":"v1.3.0","sha":"89833786a59371f05710a0a7ae636880147d54da","kind":"tag","published_at":"2020-07-10T20:09:19.000Z","download_url":"https://codeload.github.com/flitbit/json-ptr/tar.gz/v1.3.0","html_url":"https://github.com/flitbit/json-ptr/releases/tag/v1.3.0","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/flitbit%2Fjson-ptr/tags/v1.3.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/flitbit%2Fjson-ptr/tags/v1.3.0/manifests"},{"name":"v1.2.0","sha":"eff47a3d8eaf15dc1dc340c9f0cbe8d3522d3541","kind":"tag","published_at":"2019-09-14T13:17:53.000Z","download_url":"https://codeload.github.com/flitbit/json-ptr/tar.gz/v1.2.0","html_url":"https://github.com/flitbit/json-ptr/releases/tag/v1.2.0","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/flitbit%2Fjson-ptr/tags/v1.2.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/flitbit%2Fjson-ptr/tags/v1.2.0/manifests"},{"name":"v1.1.2","sha":"e3a9599f687b5ec34d988e2e7c6ef8c443f571f9","kind":"tag","published_at":"2019-03-10T16:39:38.000Z","download_url":"https://codeload.github.com/flitbit/json-ptr/tar.gz/v1.1.2","html_url":"https://github.com/flitbit/json-ptr/releases/tag/v1.1.2","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/flitbit%2Fjson-ptr/tags/v1.1.2","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/flitbit%2Fjson-ptr/tags/v1.1.2/manifests"},{"name":"v1.1.1","sha":"daf1e16615aa530be1b583a2570dea503f81a268","kind":"tag","published_at":"2018-10-14T19:12:05.000Z","download_url":"https://codeload.github.com/flitbit/json-ptr/tar.gz/v1.1.1","html_url":"https://github.com/flitbit/json-ptr/releases/tag/v1.1.1","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/flitbit%2Fjson-ptr/tags/v1.1.1","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/flitbit%2Fjson-ptr/tags/v1.1.1/manifests"},{"name":"v1.1.0","sha":"037ac352907fc8e8093ecb1777493ab2bc3a1f58","kind":"tag","published_at":"2018-02-24T21:49:30.000Z","download_url":"https://codeload.github.com/flitbit/json-ptr/tar.gz/v1.1.0","html_url":"https://github.com/flitbit/json-ptr/releases/tag/v1.1.0","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/flitbit%2Fjson-ptr/tags/v1.1.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/flitbit%2Fjson-ptr/tags/v1.1.0/manifests"},{"name":"1.0.1","sha":"062c65ee8fb04ea65478dc714c7b06d66bee6b3a","kind":"commit","published_at":"2016-07-31T14:29:08.000Z","download_url":"https://codeload.github.com/flitbit/json-ptr/tar.gz/1.0.1","html_url":"https://github.com/flitbit/json-ptr/releases/tag/1.0.1","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/flitbit%2Fjson-ptr/tags/1.0.1","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/flitbit%2Fjson-ptr/tags/1.0.1/manifests"},{"name":"v1.0.1","sha":"9661ae8e1982c66efe725682ea2da5c3dca3ea0f","kind":"tag","published_at":"2016-07-31T14:14:15.000Z","download_url":"https://codeload.github.com/flitbit/json-ptr/tar.gz/v1.0.1","html_url":"https://github.com/flitbit/json-ptr/releases/tag/v1.0.1","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/flitbit%2Fjson-ptr/tags/v1.0.1","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/flitbit%2Fjson-ptr/tags/v1.0.1/manifests"},{"name":"v1.0.0","sha":"27908bfce677cebf2c0142554fb628a3a8cbf6c3","kind":"tag","published_at":"2016-01-12T19:39:56.000Z","download_url":"https://codeload.github.com/flitbit/json-ptr/tar.gz/v1.0.0","html_url":"https://github.com/flitbit/json-ptr/releases/tag/v1.0.0","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/flitbit%2Fjson-ptr/tags/v1.0.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/flitbit%2Fjson-ptr/tags/v1.0.0/manifests"},{"name":"v0.3.1","sha":"730ccd52f4be603e2ee7266605b024973c6a3857","kind":"tag","published_at":"2016-01-04T03:55:20.000Z","download_url":"https://codeload.github.com/flitbit/json-ptr/tar.gz/v0.3.1","html_url":"https://github.com/flitbit/json-ptr/releases/tag/v0.3.1","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/flitbit%2Fjson-ptr/tags/v0.3.1","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/flitbit%2Fjson-ptr/tags/v0.3.1/manifests"},{"name":"0.3.0","sha":"77264a71004671a7845137b660372d931c694cb1","kind":"commit","published_at":"2016-01-04T03:34:47.000Z","download_url":"https://codeload.github.com/flitbit/json-ptr/tar.gz/0.3.0","html_url":"https://github.com/flitbit/json-ptr/releases/tag/0.3.0","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/flitbit%2Fjson-ptr/tags/0.3.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/flitbit%2Fjson-ptr/tags/0.3.0/manifests"},{"name":"0.2.1","sha":"6b242f64f6a65b11b7c60714b79f6bae5c1b27c9","kind":"commit","published_at":"2014-10-23T09:42:44.000Z","download_url":"https://codeload.github.com/flitbit/json-ptr/tar.gz/0.2.1","html_url":"https://github.com/flitbit/json-ptr/releases/tag/0.2.1","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/flitbit%2Fjson-ptr/tags/0.2.1","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/flitbit%2Fjson-ptr/tags/0.2.1/manifests"},{"name":"0.2.0","sha":"002846e5c11a173ee7365ee8122f2a831e12576b","kind":"commit","published_at":"2014-10-21T16:59:10.000Z","download_url":"https://codeload.github.com/flitbit/json-ptr/tar.gz/0.2.0","html_url":"https://github.com/flitbit/json-ptr/releases/tag/0.2.0","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/flitbit%2Fjson-ptr/tags/0.2.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/flitbit%2Fjson-ptr/tags/0.2.0/manifests"}]},"repo_metadata_updated_at":"2024-09-07T21:45:10.340Z","dependent_packages_count":96,"downloads":7473034,"downloads_period":"last-month","dependent_repos_count":12014,"rankings":{"downloads":0.2056954792704667,"dependent_repos_count":0.24485092899323058,"dependent_packages_count":0.38270989537787176,"stargazers_count":5.331063352195221,"forks_count":4.707582684096645,"docker_downloads_count":0.32534671403268645,"average":1.8662081756610203},"purl":"pkg:npm/json-ptr","advisories":[{"uuid":"GSA_kwCzR0hTQS04Z3dqLThoeGMtMjg1d80W4g","url":"https://github.com/advisories/GHSA-8gwj-8hxc-285w","title":"Prototype Pollution in json-ptr","description":"This affects the package `json-ptr` before `3.0.0`. A type confusion vulnerability can lead to a bypass of CVE-2020-7766 when the user-provided keys used in the pointer parameter are arrays.","origin":"UNSPECIFIED","severity":"MODERATE","published_at":"2021-11-08T17:43:27.000Z","withdrawn_at":null,"classification":"GENERAL","cvss_score":5.6,"cvss_vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L","references":["https://nvd.nist.gov/vuln/detail/CVE-2021-23509","https://github.com/flitbit/json-ptr/pull/42","https://github.com/flitbit/json-ptr/commit/5dc458fbad1c382a2e3ca6d62e66ede3d92849ca","https://github.com/flitbit/json-ptr%23security-vulnerabilities-resolved","https://snyk.io/vuln/SNYK-JS-JSONPTR-1577291","https://github.com/advisories/GHSA-8gwj-8hxc-285w"],"source_kind":"github","identifiers":["GHSA-8gwj-8hxc-285w","CVE-2021-23509"],"repository_url":"https://github.com/flitbit/json-ptr","blast_radius":0.0,"created_at":"2022-12-21T16:12:43.840Z","updated_at":"2026-06-20T04:10:32.784Z","epss_percentage":0.01769,"epss_percentile":0.75233,"api_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS04Z3dqLThoeGMtMjg1d80W4g","html_url":"https://advisories.ecosyste.ms/advisories/GSA_kwCzR0hTQS04Z3dqLThoeGMtMjg1d80W4g","packages":[{"ecosystem":"npm","package_name":"json-ptr","versions":[{"first_patched_version":"3.0.0","vulnerable_version_range":"\u003c 3.0.0"}],"purl":"pkg:npm/json-ptr"}],"related_packages_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS04Z3dqLThoeGMtMjg1d80W4g/related_packages","related_advisories":[]},{"uuid":"MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLXJycXYtdmpydy1ocmNy","url":"https://github.com/advisories/GHSA-rrqv-vjrw-hrcr","title":"Arbitrary Code Execution in json-ptr","description":"There is a security vulnerability in `json-ptr` versions prior to v2.1.0 in which an unscrupulous actor may execute arbitrary code. If your code sends un-sanitized user input to json-ptr's .get() method, your project is vulnerable to this injection-style vulnerability.","origin":"UNSPECIFIED","severity":"HIGH","published_at":"2021-05-26T19:59:19.000Z","withdrawn_at":null,"classification":"GENERAL","cvss_score":0.0,"cvss_vector":null,"references":["https://github.com/418sec/json-ptr/pull/3","https://github.com/flitbit/json-ptr/blob/456a1728b45c8663bb1ac20a249c5fb17495ec6b/README.md#security-vulnerability-prior-to-v210","https://github.com/flitbit/json-ptr/blob/master/src/util.ts%23L174","https://snyk.io/vuln/SNYK-JAVA-ORGWEBJARSNPM-1038396","https://snyk.io/vuln/SNYK-JS-JSONPTR-1016939","https://www.huntr.dev/bounties/2-npm-json-ptr/","https://www.npmjs.com/advisories/1706","https://www.npmjs.com/package/json-ptr","https://github.com/advisories/GHSA-rrqv-vjrw-hrcr"],"source_kind":"github","identifiers":["GHSA-rrqv-vjrw-hrcr"],"repository_url":"https://github.com/418sec/json-ptr","blast_radius":0.0,"created_at":"2022-12-21T16:13:00.417Z","updated_at":"2026-05-04T17:10:48.804Z","epss_percentage":null,"epss_percentile":null,"api_url":"https://advisories.ecosyste.ms/api/v1/advisories/MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLXJycXYtdmpydy1ocmNy","html_url":"https://advisories.ecosyste.ms/advisories/MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLXJycXYtdmpydy1ocmNy","packages":[{"ecosystem":"npm","package_name":"json-ptr","versions":[{"first_patched_version":"2.1.0","vulnerable_version_range":"\u003c 2.1.0"}],"purl":"pkg:npm/json-ptr"}],"related_packages_url":"https://advisories.ecosyste.ms/api/v1/advisories/MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLXJycXYtdmpydy1ocmNy/related_packages","related_advisories":[]},{"uuid":"MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLXg1cjYteDgyMy05ODQ4","url":"https://github.com/advisories/GHSA-x5r6-x823-9848","title":"Arbitrary Code Execution in json-ptr","description":"npm `json-ptr` before 2.1.0 has an arbitrary code execution vulnerability. The issue occurs in the [set operation](https://flitbit.github.io/json-ptr/classes/_src_pointer_.jsonpointer.htmlset) when the force flag is set to true. The function recursively set the property in the target object, however it does not properly check the key being set, leading to a prototype pollution.","origin":"UNSPECIFIED","severity":"HIGH","published_at":"2021-05-10T19:15:43.000Z","withdrawn_at":null,"classification":"GENERAL","cvss_score":7.3,"cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L","references":["https://nvd.nist.gov/vuln/detail/CVE-2020-7766","https://github.com/418sec/json-ptr/pull/3","https://github.com/flitbit/json-ptr/blob/master/src/util.ts%23L174","https://snyk.io/vuln/SNYK-JAVA-ORGWEBJARSNPM-1038396","https://snyk.io/vuln/SNYK-JS-JSONPTR-1016939","https://www.npmjs.com/package/json-ptr","https://www.huntr.dev/bounties/2-npm-json-ptr/","https://github.com/flitbit/json-ptr/commit/2539e3494c80af1eef24f0f433654a61f255f011","https://github.com/advisories/GHSA-x5r6-x823-9848"],"source_kind":"github","identifiers":["GHSA-x5r6-x823-9848","CVE-2020-7766"],"repository_url":"https://github.com/418sec/json-ptr","blast_radius":0.0,"created_at":"2022-12-21T16:13:00.409Z","updated_at":"2026-06-20T04:08:07.422Z","epss_percentage":0.01879,"epss_percentile":0.76731,"api_url":"https://advisories.ecosyste.ms/api/v1/advisories/MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLXg1cjYteDgyMy05ODQ4","html_url":"https://advisories.ecosyste.ms/advisories/MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLXg1cjYteDgyMy05ODQ4","packages":[{"ecosystem":"npm","package_name":"json-ptr","versions":[{"first_patched_version":"2.1.0","vulnerable_version_range":"\u003c 2.1.0"}],"purl":"pkg:npm/json-ptr"}],"related_packages_url":"https://advisories.ecosyste.ms/api/v1/advisories/MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLXg1cjYteDgyMy05ODQ4/related_packages","related_advisories":[]}],"docker_usage_url":"https://docker.ecosyste.ms/usage/npm/json-ptr","docker_dependents_count":155,"docker_downloads_count":24860797,"usage_url":"https://repos.ecosyste.ms/usage/npm/json-ptr","dependent_repositories_url":"https://repos.ecosyste.ms/api/v1/usage/npm/json-ptr/dependencies","status":"deprecated","funding_links":[],"critical":null,"issue_metadata":{"last_synced_at":"2024-09-06T19:10:08.311Z","issues_count":22,"pull_requests_count":35,"avg_time_to_close_issue":7694149.476190476,"avg_time_to_close_pull_request":6001918.193548387,"issues_closed_count":21,"pull_requests_closed_count":31,"pull_request_authors_count":16,"issue_authors_count":20,"avg_comments_per_issue":2.8636363636363638,"avg_comments_per_pull_request":1.0857142857142856,"merged_pull_requests_count":20,"bot_issues_count":0,"bot_pull_requests_count":13,"past_year_issues_count":0,"past_year_pull_requests_count":0,"past_year_avg_time_to_close_issue":null,"past_year_avg_time_to_close_pull_request":null,"past_year_issues_closed_count":0,"past_year_pull_requests_closed_count":0,"past_year_pull_request_authors_count":0,"past_year_issue_authors_count":0,"past_year_avg_comments_per_issue":null,"past_year_avg_comments_per_pull_request":null,"past_year_bot_issues_count":0,"past_year_bot_pull_requests_count":0,"past_year_merged_pull_requests_count":0,"issues_url":"https://issues.ecosyste.ms/api/v1/hosts/GitHub/repositories/flitbit%2Fjson-ptr/issues","maintainers":[{"login":"flitbit","count":1,"url":"https://issues.ecosyste.ms/api/v1/hosts/GitHub/authors/flitbit"}],"active_maintainers":[]},"versions_url":"https://packages.ecosyste.ms/api/v1/registries/npmjs.org/packages/json-ptr/versions","version_numbers_url":"https://packages.ecosyste.ms/api/v1/registries/npmjs.org/packages/json-ptr/version_numbers","latest_version_url":"https://packages.ecosyste.ms/api/v1/registries/npmjs.org/packages/json-ptr/latest_version","dependent_packages_url":"https://packages.ecosyste.ms/api/v1/registries/npmjs.org/packages/json-ptr/dependent_packages","related_packages_url":"https://packages.ecosyste.ms/api/v1/registries/npmjs.org/packages/json-ptr/related_packages","codemeta_url":"https://packages.ecosyste.ms/api/v1/registries/npmjs.org/packages/json-ptr/codemeta","maintainers":[{"uuid":"cerebralkungfu","login":"cerebralkungfu","name":null,"email":"phillip@flitbit.com","url":null,"packages_count":15,"html_url":"https://www.npmjs.com/~cerebralkungfu","role":null,"created_at":"2022-11-12T23:08:55.095Z","updated_at":"2022-11-12T23:08:55.095Z","packages_url":"https://packages.ecosyste.ms/api/v1/registries/npmjs.org/maintainers/cerebralkungfu/packages"}]}